Frontiers of Data and Computing ›› 2024, Vol. 6 ›› Issue (6): 97-108.

CSTR: 32002.14.jfdc.CN10-1649/TP.2024.06.010

doi: 10.11871/jfdc.issn.2096-742X.2024.06.010

Previous Articles     Next Articles

Attribute-Based SASE Access Control and Dynamic Routing Technology

JIN Shenghao(),ZHENG Yu,TU Yu,ZHANG Hui*()   

  1. State Key Laboratory of Complex & Critical Software Environment, Beihang University, Beijing 100191, China
  • Received:2024-03-28 Online:2024-12-20 Published:2024-12-20
  • Contact: ZHANG Hui E-mail:sh@buaa.edu.cn;hzhang@buaa.edu.cn

Abstract:

[Objective] In recent years, the traditional enterprise network structure has been completely subverted, and the concept of Secure Access Service Edge (SASE), which integrates the dynamic networking capability of wide area network and comprehensive network security services, has been proposed. In this paper, we focus on the access control and dynamic routing requirements of SASE. [Methods] This paper proposes an attribute-based approach for dynamic secure network access technology by defining “attributes” to describe the entity identity and real-time context in the SASE environment. Firstly, attribute-based access control technology is designed to support the dynamic fine-grained access control function of SASE. Then, an attribute-based dynamic routing architecture is designed, which can make dynamic routing decisions by combining the attributes carried by entities such as data packets, network environment, senders and receivers, providing basic support for the traffic scheduling and service orchestration functions of SASE. [Results] Finally, the feasibility validation results demonstrate that the total bandwidth loss rate of the proposed technical approach is about 4.04%, the peak network jitter is 1.534 ms, and the peak packet loss rate is 0.825%, all of which are in the reasonable range. [Conclusions] This technical approach has no significant impact on the network performance while significantly improving the network security and dynamics, and is of practical value.

Key words: secure access service edge, attribute-based access control, attribute-based routing