Model for access control policy refinement based on domain and its implementation

Kuang Y. Zeng,Jinxiang Zhang,Jiahai Yang
2006-01-01
Abstract:A new model for policy refinement is presented at the application background of CERNET. Using the properties of access control list (ACL) in this model, the policies described in different specification languages are mapped into access control lists, which are distributed to different network devices to enforce. Thus, the complex transformation logic in traditional policy refinement fashion is simplified, especially, security and access control configuration management can be automated.
What problem does this paper attempt to address?