INTERDOMAIN GUARDIANS IN A DISTRIBUTED DIRECTORY SERVICE

被引:0
|
作者
CHADWICK, DW [1 ]
POPE, NH [1 ]
机构
[1] SECUR & STAND,CHELMSFORD CM2 0LG,ESSEX,ENGLAND
关键词
APPLICATION LAYER COMMUNICATION SERVICES; DIRECTORY SERVICES; SECURITY ASPECTS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The joint ISO/CCITT X.500 Directory Standard defines a highly distributed directory service. It provides easy access to names and addresses which can be distributed across directory system components potentially anywhere in the world. In general there is minimal control over the flow of directory information amongst directory system components. However, in practice there is a need to restrict the flow of directory information between domains whilst maintaining the advantages of a global directory service. This paper considers possible trust relationships between domains and describes the design of a Guardian DSA that can be used to restrict the flow of names and addresses in and out of a security domain without compromising the service available to users. In most situations a Guardian DSA operates as a restricted version of a standard directory component. In only one case, forwarding of an outgoing chained request, may a Guardian DSA act differently from a standard DSA.
引用
收藏
页码:347 / 365
页数:19
相关论文
共 50 条
  • [1] OPENDIR: An open distributed service directory
    Ardon, S
    Portmann, M
    Rakotoarivelo, T
    Senac, P
    Zhou, S
    Hogan, A
    Seneviratne, A
    2005 3rd IEEE International Conference on Industrial Informatics (INDIN), 2005, : 110 - 116
  • [2] Distributed directory service in the farsite file system
    Douceur, John R.
    Howell, Jon
    USENIX ASSOCIATION 7TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2006, : 321 - +
  • [3] Distributed and Scalable Directory Service in a Parallel File System
    Wang, Lixin
    Lu, Yutong
    Zhang, Wei
    Lei, Yan
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (02): : 313 - 323
  • [4] Replicated directory service for weakly consistent distributed caches
    Makpangou, M
    Pierre, G
    Khoury, C
    Dorta, N
    19TH IEEE INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 1999, : 92 - 100
  • [5] SUPPORTING NETWORK MANAGEMENT THROUGH DISTRIBUTED DIRECTORY SERVICE
    ZHANG, XX
    SERET, D
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 1994, 12 (06) : 1000 - 1010
  • [6] Distributed directory service and message routing for mobile agents
    Moreau, L
    SCIENCE OF COMPUTER PROGRAMMING, 2001, 39 (2-3) : 249 - 272
  • [7] Design of a secure distributed service directory for wireless sensornetworks
    Hof, HJ
    Blass, EO
    Fuhrmann, T
    Zitterbart, M
    WIRELESS SENSOR NETWORKS, PROCEEDINGS, 2004, 2920 : 276 - 290
  • [8] Distributed directory service and message routing for mobile agents
    Moreau, Luc, 1600, Elsevier Science B.V., Amsterdam, Netherlands (39): : 2 - 3
  • [9] Replicated directory service for weakly consistent distributed caches
    Makpangou, Mesaac
    Pierre, Guillaume
    Khoury, Christian
    Dorta, Neilze
    Proceedings - International Conference on Distributed Computing Systems, 1999, : 92 - 100
  • [10] Channel reflector: An interdomain channel directory system
    Asaeda, Hitoshi
    Pokavanich, Wacharapol
    Yamamoto, Soh
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2006, E89B (10) : 2860 - 2867