A Reconfigurable and Dynamic Access Control Model in the Programmable Data Plane

Xincheng Yan,Na Zhou,Zhihong Jiang,Letian Li,Ying Liu
DOI: https://doi.org/10.1007/978-981-19-9697-9_38
2023-01-01
Abstract:The explosive growth of various emerging online services has created severe challenges in terms of flexibility and scalability of access control. In order to break through the drawbacks of static and redundancy in traditional access control, we implement an endogenous network access control mechanism based on a reconfigurable decision tree model. First, we explored how to optimize the deployment of access control policies, choosing a decision tree model as the judge based on the network architecture. Second, the authorization decision procedure running on the control plane is migrated to the forwarding device located in the data plane, which can reduce the processing delay. Finally, experiments in the simulation environment show that our scheme can implement access control with less memory overhead, has higher correctness, and has less impact on forwarding than the alternative schemes.
What problem does this paper attempt to address?