Netinfo Security ›› 2021, Vol. 21 ›› Issue (10): 33-40.doi: 10.3969/j.issn.1671-1122.2021.10.005

Previous Articles     Next Articles

Resource Access Control Scheme Based on User Credit in SDN

WEI Zhanzhen, PENG Xingyuan, ZHAO Hong()   

  1. Beijing Electronic Science and Technology Institute, Beijing 100070, China
  • Received:2021-04-12 Online:2021-10-10 Published:2021-10-14
  • Contact: ZHAO Hong E-mail:zh@besti.edu.cn

Abstract:

Existing resource access control schemes have problems such as the inability to dynamically change user access permissions, and the security risks in the formulation of access control policies. In view of these problems, this paper proposes a resource access control scheme based on user credit in SDN. This scheme introduces the concept of user credit and uses the characteristics of SDN that management and control separation and flow-driven to design a resource access control system based on user credit. The controller evaluates the user’s credit based on the user’s attributes, and classifies users accordingly. By issuing flow tables, different types of users are granted different permissions. When the user’s trust level changes, their access permissions will also change, realizing the function of dynamically granting permissions. And the program is simulated through Mininet and compares it with ordinary SDN networks and traditional networks, the results show that the program has a certain degree of dynamics and security in resource access control.

Key words: SDN, access control, user credit, dynamic authorization

CLC Number: