摘要
传统VPN的接入控制依赖于身份认证,而未考虑终端环境的动态变化,未能将客户终端的安全融入到VPN结构中去.本文提出DEAC(Dynamic Endpoint Admission Control,动态端点准入控制)机制,将终端安全状况和整个VPN系统相关联,使得VPN能够感知客户终端环境的变化,依靠具体情况动态实施访问控制;由终端环境和VPN服务构成一个整体,提高VPN拓扑的安全性.
Entry control on traditional VPN bases on authentication. It has not considered the dynamic change of end environment and can not conform the security of user's terminal conditions to VPN framework. This paper presents DEAC(Dynamic Endpoint Admission Control), which correlates the end security to the whole VPN system. DEAC makes VPN apperceive the variety of user's terminal and implement dynamic access control by material instances. End environment and VPN service compose into one whole to improve the security of the VPN topology.
出处
《小型微型计算机系统》
CSCD
北大核心
2007年第8期1377-1381,共5页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目(60373088)资助