Deakin University
Browse

Towards policy enforcement point as a service (PEPS)

Version 2 2024-06-12, 18:41
Version 1 2016-01-01, 00:00
conference contribution
posted on 2024-06-12, 18:41 authored by A Shaghaghi, MA Kaafar, S Scott-Hayward, SS Kanhere, S Jha
In this paper, we coin the term Policy Enforcement as a Service (PEPS), which enables the provision of innovative inter-layer and inter-domain Access Control. We leverage the architecture of Software-Defined-Network (SDN) to introduce a common network-level enforcement point, which is made available to a range of access control systems. With our PEPS model, it is possible to have a 'defense in depth' protection model and drop unsuccessful access requests before engaging the data provider (e.g. a database system). Moreover, the current implementation of access control within the 'trusted' perimeter of an organization is no longer a restriction so that the potential for novel, distributed and cooperative security services can be realized. We conduct an analysis of the security requirements and technical challenges for implementing Policy Enforcement as a Service. To illustrate the benefits of our proposal in practice, we include a report on our prototype PEPS-enabled location-based access control.

History

Related Materials

Location

Palo Alto, Calif.

Language

eng

Publication classification

E1.1 Full written paper - refereed

Copyright notice

2016, IEEE

Editor/Contributor(s)

[Unknown]

Pagination

50-55

Start date

2016-11-07

End date

2016-11-10

ISBN-13

9781509009336

Title of proceedings

IEEE NFV-SDN 2016 : Proceedings of the 2016 IEEE Conference on Network Function Virtualization and Software Defined Networks

Event

IEEE Communcations Society. Conference (2016 : Palo Alto, Calif.)

Publisher

Institute of Electrical and Electronics Engineers

Place of publication

Piscataway, N.J.

Series

IEEE Communcations Society Conference

Usage metrics

    Research Publications

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC