With the rapid development of Virtual Private Network (VPN), many companies and organizations use VPN to implement their private communication. Traditionally, VPN uses security protocols to protect the confidentiality...With the rapid development of Virtual Private Network (VPN), many companies and organizations use VPN to implement their private communication. Traditionally, VPN uses security protocols to protect the confidentiality of data, the message integrity and the endpoint authentication. One core technique of VPN is tunneling, by which clients can access the in- ternal servers traversing VPN. However, the tunneling technique also introduces a concealed security hole. It is possible that if one vicious user can establish tunneling by the VPN server, he can compromise the internal servers behind the VPN server. So this paper presents a novel Application-layer based Centralized Information Access Control (ACIAC) for VPN to solve this problem. To implement an efficient, flexible and multi-decision access control model, we present two key techniques to ACIAC—the centralized management mechanism and the stream-based access control. Firstly, we implement the information center and the constraints/events center for ACIAC. By the two centers, we can provide an abstract access control mechanism, and the material access control can be decided dynamically by the ACIAC’s constraint/event mechanism. Then we logically classify the VPN communication traffic into the access stream and the data stream so that we can tightly couple the features of VPN communication with the access control model. We also provide the design of our ACIAC prototype in this paper.展开更多
随着第四代移动通信系统(The fourth generation mobile communication system,4G)长期演进技术(Long term evolution,LTE)在全球商用的成功展开和移动数据的爆发式增长,对第五代移动通信系统(The fifth generation mobile communicatio...随着第四代移动通信系统(The fourth generation mobile communication system,4G)长期演进技术(Long term evolution,LTE)在全球商用的成功展开和移动数据的爆发式增长,对第五代移动通信系统(The fifth generation mobile communication system,5G)的研发提上日程。本文首先分析了5G发展的两个驱动力,介绍了国际电联(International telecommunication union,ITU)对5G标准化的规划和最新进展,总结了通信业界与学术界公认的5G关键技术,并对其中的无线网络相关技术,超密集蜂窝(Ultra dense cellular network,UDN)和集中式蜂窝架构的研究进行了深入的分析介绍。最后总结了5G的发展趋势和未来的研究动向。展开更多
基金Project (No. 60373088) supported by the National Natural ScienceFoundation of China
文摘With the rapid development of Virtual Private Network (VPN), many companies and organizations use VPN to implement their private communication. Traditionally, VPN uses security protocols to protect the confidentiality of data, the message integrity and the endpoint authentication. One core technique of VPN is tunneling, by which clients can access the in- ternal servers traversing VPN. However, the tunneling technique also introduces a concealed security hole. It is possible that if one vicious user can establish tunneling by the VPN server, he can compromise the internal servers behind the VPN server. So this paper presents a novel Application-layer based Centralized Information Access Control (ACIAC) for VPN to solve this problem. To implement an efficient, flexible and multi-decision access control model, we present two key techniques to ACIAC—the centralized management mechanism and the stream-based access control. Firstly, we implement the information center and the constraints/events center for ACIAC. By the two centers, we can provide an abstract access control mechanism, and the material access control can be decided dynamically by the ACIAC’s constraint/event mechanism. Then we logically classify the VPN communication traffic into the access stream and the data stream so that we can tightly couple the features of VPN communication with the access control model. We also provide the design of our ACIAC prototype in this paper.
文摘随着第四代移动通信系统(The fourth generation mobile communication system,4G)长期演进技术(Long term evolution,LTE)在全球商用的成功展开和移动数据的爆发式增长,对第五代移动通信系统(The fifth generation mobile communication system,5G)的研发提上日程。本文首先分析了5G发展的两个驱动力,介绍了国际电联(International telecommunication union,ITU)对5G标准化的规划和最新进展,总结了通信业界与学术界公认的5G关键技术,并对其中的无线网络相关技术,超密集蜂窝(Ultra dense cellular network,UDN)和集中式蜂窝架构的研究进行了深入的分析介绍。最后总结了5G的发展趋势和未来的研究动向。