- Book Chapter
- 10.1016/b978-193183663-0/50040-2
Chapter 5 - Configuring Authentication, Authorization, and Accounting
- Jan 01, 2002
- Cisco Security Specialists Guide to PIX Firewall
Chapter 5 - Configuring Authentication, Authorization, and Accounting
In recent years, there has been a growing demand for the development of authentication, authorization and accounting (AAA) systems for WLAN networks. In this paper we present a network architecture of SQL database servers especially tailored for AAA functions in large WLAN systems. Proposed database network architecture is vendor independent in sense that can be deployed with different AAA server implementations. WLAN management information database for AAA purposes is center of a WLAN network management system providing control of parameters such as: authentication and authorization of users, deletion or creation of users information, storage of accounting information which can be used for billing. Detailed database structure of each SQL database server in proposed centralized-distributed AAA database network architecture is described. Working principles of network database system for WLAN AAA purposes are based on MySQL master/slave chain replication. Proposed network architecture of SQL databases offers high level of reliability, availability and scalability.
Chapter 5 - Configuring Authentication, Authorization, and Accounting
Chapter 5 - Configuring Authentication, Authorization, and Accounting
An AAA solution for securing industrial IoT devices using next generation access control
Industry 4.0 is advancing the use of Internet of Things (IoT) devices in industrial applications, which enables efficient device-to-device (D2D) communication. However, these devices are often heterogeneous in nature, i.e. from different manufacturers, use different protocols, etc. and adds requirements such as security, interoperability, etc. To address these requirements, the Service-Oriented Architecture-Based (SOA) Arrowhead Framework was previously proposed using the concept of local clouds. These local clouds provide a set of mandatory and support core systems to enable industrial automation applications. One of these mandatory core systems is an Authentication, Authorisation and Accounting (AAA) system, which is used to authenticate and provide access control to the devices in a local cloud. In an industrial context, with multiple stakeholders, the AAA must support fine-grain access control. For example, in a distributed control loop, a controller should only have read access to its sensor such as a flow meter and write access to its actuator, such as a valve. The controller should not have access to any other information besides what is needed to implement the desired functionality. In this work, an NGAC-based AAA solution to achieve fine-grain service level access control between IoT devices has been proposed and implemented. The solution is presented using a district heating use case.
Read moreDiameter Network Address and Port Translation Control Application
This document describes the framework, messages, and procedures for the Diameter Network address and port translation Control Application. This Diameter application allows per-endpoint control of Network Address Translators and Network Address and Port Translators, which are added to networks to cope with IPv4 address space depletion. This Diameter application allows external devices to configure and manage a Network Address Translator device -- expanding the existing Diameter- based Authentication, Authorization, and Accounting (AAA) and policy control capabilities with a Network Address Translator and Network Address and Port Translator control component. These external devices can be network elements in the data plane such as a Network Access Server, or can be more centralized control plane devices such as AAA- servers. This Diameter application establishes a context to commonly identify and manage endpoints on a gateway or server and a Network Address Translator and Network Address and Port Translator device. This includes, for example, the control of the total number of Network Address Translator bindings allowed or the allocation of a specific Network Address Translator binding for a particular endpoint. In addition, it allows Network Address Translator devices to provide information relevant to accounting purposes. [STANDARDS-TRACK]
Read moreImplementation of AAA Server for PMIPv6 in NS-2
Proxy Mobile IPv6 is a network-based mobility protocol where the mobility management signaling is performed by a network entity on behalf of the node requiring mobility itself. Mobile IPv6 (MIPv6) enables Mobile Node (MN) to maintain its connectivity to the Internet during handover. The Mobile Access Gateway (MAG), located in the access router, retrieves the MN profile information from Authentication, Authorization, and Accounting (AAA) server and sends the customized Router Advertisements to the MN, emulating the home network behavior. Theoretically there is an inclusion of AAA server in PMIPV6 but the practical inclusion is not been attempted yet, hence this paper proposes an architecture for including the AAA server into the NS2 for PMIPV6.
Read moreAuthentication Protocols for Mobile IP Networks
In this paper, we propose a novel 2-way handshake authentication protocol to locally authorize intra-domain roaming users for efficient authentication in mobile IP networks, which is based on authentication, authorization and accounting (AAA) architecture. The performance evaluation shows that our protocol outperforms the existing authentication protocols.
Read moreOn Implementing IPTV Platform with IPv4 and IPv6 Devices
The end of IPv4 addresses is now a reality. Providers not updated to IPv6 will have to hurry up the IPv6 start in its own network. Introduction of IPv6 means not only change of main routers but also change of mentality in operators, applications’ programmers besides end users. Even when for the last years the core network is prepared for transferring IPv6 traffic, other built-in parts of the Internet limit the IPv6 start. Examples of these limitations we find in not IPv6-awareness of many applications and services. For instance, voice over IP service, which uses session initiation protocol (SIP) needs to implement IPv6 aware SIP proxies and IPv6 aware AAA (authentication, authorization and accounting) servers as well as adapting application programming interfaces to IPv6. Internet protocol television (IPTV) system includes many different hardware devices, which not always are IPv6 compatible. In this paper, we propose a global solution for integrating all the devices, these one working on IPv4 and these one working on IPv6, under the same IPTV platform. This solution allows end users to receive IPTV stream irrespective of IP protocol used. The proposed solution is particularly relevant for small IPTV systems, which, step by step, are adapting into IPv6.
Read moreReview of Data Security and Privacy in Cloud Computing
Cloud computing, thus, ensure more healthy demand for cloud services, certain measures against threats in order to protect information must be taken. In essence, the current paper seeks to extend knowledge regarding the improvement of paradigms of cloud computing with particular focus on the aspect of certification of authentic users and protection of the contents that are hosted in these environments. It mentions a new approach in the context of the authentication method that was deployed for the purpose of the AAA certification is presented there along with the watermarking and this RSA algorithms to enhance the security of the cloud file-sharing. This concept is far more effective than the conventional access policies that are top down and cal beforehand for systematic risk avoidance; hence, it helps to minimize the chances of an organization being vulnerable to various risks by right management. Iturbide’s data loss prevention technique eliminates the probability of losing sensitive information to the rest of the world as well as other unauthorized persons or organizations regaining access to privileged keys while Shamir’s secret sharing algorithm- polynomial interpolation ensures that the generation of keys is not a time-consuming exercise. In order to address the issues of persistent security threats in cloud computing paradigm, the proposed model includes computation, encryption and access to improve the overall security of cloud environment. However, these measures have been implemented, some of them can offer the best security when it comes to the ever-evolving threat. To maintain the privacy of clients’ data in the CL reinforcement learning, the paper suggests the use of homomorphic encryption for privacy-preserving RL inference. Therefore – as a result of the work – the necessity of implementing the suggested security model for the cloud computing environments as well as protecting the data and enhancing the level of trust in cloud solutions is stated. Keywords - QoS (Quality of Service), Energy Efficiency, Ontology, AAA (Authentication, Authorization, and Accounting), RSA Algorithm, RSA Algorithm, ReDCIM (Reconfigurable Digital Computing-In-Memory) Processor, tableopencache, LSTM (Long Short-Term Memory)
Read moreReview and Reflections
This chapter provides a brief review and synthesis of the preceding chapters followed by some thoughts on the future development of social and environmental accounting and accountability systems. The preceding chapters attempt to stimulate dialog and debate regarding corporate social responsibility, sustainability, ethics and governance. The authors recognize the need for, and issues associated with, expanding accounting and accountability systems with the goal of advancing social, environmental and economic justice. The second section in this chapter extends the conversation on accountability and social and environmental issues, proposing to reorient the conversation toward accountability-based accounting away from accounting-based accountability.
Read moreMethods of processing various data in intelligent systems for management of the network and server architecture of the internet of combat things
In this chapter of the research, a method of processing various types of data in intelligent management systems of the network and server architecture of the internet of military equipment is proposed. The basis of this research is the theory of artificial intelligence, namely evolving artificial neural networks, basic genetic algorithm procedures, neuro-fuzzy expert systems, as well as bio-inspired algorithms. In the course of the research, the authors proposed:– a complex model of processing various types of data in intelligent decision-making support systems;– a method of processing various types of data in intelligent management systems of network and server architecture;– a method of increasing the efficiency of processing various types of data in intelligent management systems of network and server architecture. The use of methods of processing various types of data in intelligent management systems of the network and server architecture of the internet of military equipment:– to reduce the probability of premature convergence of the metaheuristic algorithm while processing various types of data in intelligent management systems of the network and server architecture of the internet of military equipment;– to maintain a balance between the speed of convergence of the metaheuristic algorithm and diversification while processing various types of data in the intelligent control systems of the network and server architecture of the internet of military equipment;– to take into account the type of uncertainty and noise of the data of the metaheuristic algorithm while processing various types of data in the intelligent control systems of the network and server architecture of the internet of military equipment;– to take into account the available computing resources of the system while processing various types of data in the intelligent management systems of the network and server architecture of the internet of military equipment;– to take into account the priority of search by swarm agents of the meta-heuristic algorithm while processing various types of data in intelligent management systems of the network and server architecture of the internet of military equipment;– to conduct an initial display of flock individuals taking into account the type of uncertainty;– to conduct accurate training of metaheuristic algorithms;– to conduct a local and global search taking into account the degree of data noise while processing various types of data in intelligent management systems of the network and server architecture of the internet of military equipment.
Read moreANALISIS SISTEM AKUNTANSI DAN PENGELOLAAN KEUANGAN UMKMSTUDI KASUS PADA PABRIK OMAH OBLONG YOGYAKARTA
This study aims to analyze the accounting system and financial management of SMEs, with a case study of Omah Oblong Factory in Yogyakarta. A sound accounting system is a crucial factor in improving the financial performance of SMEs. This research adopts a qualitative approach with a case study method. Data were collected through in-depth interviews, direct observation, and financial document analysis. The results indicate that Omah Oblong Factory employs a basic manual accounting system, but it exhibits several weaknesses, such as limited use of information technology and financial literacy. Financial management demonstrates a clear separation between revenue and expenses, though it is not fully integrated. By enhancing the use of information technology and providing financial literacy training, Omah Oblong Factory is expected to improve the efficiency of its accounting system and financial performance. This study offers strategic recommendations for the development of SME accounting systems in the future.
Read moreEnergy Efficient AR/VR Edge Processing: Architecture and Optimization
This article introduces a server-centric cellular Passive Optical Network (C-PON) architecture to support the deployment of Augmented Reality (AR)/ Virtual Reality (VR) event viewing applications in edge data centers. The proposed architecture is compared with the state-of-the-art Spine-and-Leaf architecture. For fair comparison, we model production style environments based on both C-PON and Spine-and-leaf data center architectures. We developed a Mixed Integer Linear Programming (MILP) model with multi-objective function to optimize routing of AR/VR traffic on both C-PON and Spine-and-Leaf architectures. The multi-objective function considers minimizing power consumption and minimizing end-to-end delay within the network architectures. We compare hosting the AR/VR applications in C-PON and in Spine-and-Leaf in terms of the power consumption, the average delay in links, and the end-to-end delay per user. We also developed a heuristic algorithm to enhance the scalability enabling the optimization of complex and larger systems. The results show that C-PON can enable substantial savings in terms of power consumption compared to the state-of-the-art Spine-and-Leaf architecture.
Read moreModular sensor architecture for unobtrusive routine clinical diagnosis
Clinical diagnosis of pathological conditions is accomplished regularly via the recording and subsequent analysis of a physiological variable from a subject. Problems with current common practice centre around the obtrusive and rigid nature of this process. These include the length, timing and location of the diagnostic recording session, transfer of data to clinical staff, liaison between clinical staff and subjects and the integration of such diagnostic check-ups into the overall health care process. We have designed a modular diagnostic monitor that is centered around a wearable computer system which, when integrated into a suitable computer network and database architecture, is capable of addressing the above problems. The system is modular, allowing researchers and practitioners to utilise various sensor modules, reconfigure the unit in terms of its on-board storage and wireless telemetry capabilities, select the appropriate level of data preprocessing (before archiving data) and choose the appropriate level and nature of feedback to the subject. The system is GRID enabled, supporting e-clinical-trials. GRID clients can display live data, historical data, or perform data mining.
Read moreResearch of Accounting and Control Support for Equity Management of a Commercial Company
The efficiency of equity management of any commercial organization largely depends on the information generated within its accounting and control system (ACS). The paper describes the study of accounting and control support for managing a company’s equity capital. The theoretical and methodological basis of the study bottoms on works of scientists in the researching scape, regulatory legal acts on accounting and auditing in the Russian Federation. The work clarifies the conceptual apparatus, an interrelation the notions as ‘accounting and control support’ and ‘accounting and control system’; founds a place of the last notion in the system of information management of a commercial company as well as the author defines the concept of ‘accounting and control support of equity capital management’. Moreover, there have been identified factors affecting the set of specific tools which have been using in the accounting and control system of each commercial company. The main results of the study can be used by chief accountants and auditors in the development and improvement of accounting and internal control system of a commercial company.
Read moreService level agreement trading for the differentiated services architectures
The differentiated services (DS) architecture provides a framework for the scalable provisioning of multiple service levels in the Internet. Its definition and initial work have concentrated mainly on per-hop behaviors (PHB) and mechanisms at each DS domain. Equally important is what happens between DS domains. Thanks to the flexibility of the architecture, it is the providers’ choice how to interconnect with peers. In principle, traditional, static peering agreements work together with DS, but they do not offer the flexibility and dynamics needed in an electronic market for network capacity. Therefore, we look at dynamic service level agreements at the interdomain level. Such agreements are established by software entities called traders. These traders follow market-based principles to decide which contracts will be beneficial. In particular, traders compare the offers made by neighbor providers and select the most interesting ones. This selection of peer services creates competition among providers and integrates route selection based on service level and destination. We describe and implement a framework for service level agreement trading. We show the basic workings and first performance results of SLA trading using specific traders and an experimentally defined PHB in a simulation environment. Keywords— Network architecture, differentiated services architecture, service level agreement, pricing, trading, interdomain QoS routing.
Read morePresentation Attack Detection Framework
Biometric-based authentication systems are becoming the preferred choice to replace password-based authentication systems. Among several variations of biometrics (e.g., face, eye, fingerprint), iris-based authentication is commonly used in every day applications. In iris-based authentication systems, iris images from legitimate users are captured and certain features are extracted to be used for matching during the authentication process. Literature works suggest that iris-based authentication systems can be subject to presentation attacks where an attacker obtains printed copy of the victim’s eye image and displays it in front of an authentication system to gain unauthorized access. Such attacks can be performed by displaying static eye images on mobile devices or iPad (known as screen attacks). As iris features are not changed, once an iris feature is compromised, it is hard to avoid this type of attack. Existing approaches relying on static features of the iris are not suitable to prevent presentation attacks. Feature from live Iris (or liveness detection) is a promising approach. Further, additional layer of security from iris feature can enable hardening the security of authentication system that existing works do not address. To address these limitations, this chapter introduces iris signature generation based on the area between the pupil and the cornea. Our approach relies on capturing iris images using near infrared light. We train two classifiers to capture the area between the pupil and the cornea. The image of iris is then stored in the database. This approach generates a QR code from the iris. The code acts as a password (additional layer of security) and a user is required to provide it during authentication. The approach has been tested using samples obtained from publicly available iris database. The initial results show that the proposed approach has lower false positive and false negative rates.
Read more