Network security policy for large-scale VPN

Rongsheng Shan,Shenghong Li,Mingzheng Wang,Jianhua Li
DOI: https://doi.org/10.1109/ICCT.2003.1209071
2003-01-01
Abstract:In the current VPN, manual security policy configuration is usually inefficient and error-prone. The paper studies the problem of conflicts among policies in different domains of a large-scale VPN. In this paper, a new trusted domain and a novel security transmission model as the fundament of the security theory of VPN are defined, and based on them, the exact definition of security transmission requirements and the corresponding effective security policies for a large-scale VPN are proposed. In addition, this paper gives the principles of policy verification for the purpose of checking the consistence of security policies in the whole network environment.
What problem does this paper attempt to address?