The Experts below are selected from a list of 222480 Experts worldwide ranked by ideXlab platform

Cees De Laat - One of the best experts on this subject based on the ideXlab platform.

  • xacml policy profile for multidomain Network Resource provisioning and supporting authorisation infrastructure
    IEEE International Symposium on Policies for Distributed Systems and Networks, 2009
    Co-Authors: Yuri Demchenko, Mihai Cristea, Cees De Laat
    Abstract:

    Policy definition is an important component of the consistent authorisation service infrastructure that could be effectively integrated with the general Resource provisioning workflow and Network control and management plane. The paper describes the proposed XACML-NRP policy and attributes profile for Network Resource Provisioning. In addition to specifying a set of subject, Resource, action attributes that are required for consistent XACML policy definition, the proposed profile allows also handling Network path information what is especially important for QoS enforcement. To overcome stateless character of XACML policies, the proposed authorisation infrastructure provides a number of security mechanisms to support such important for NRP functionality as authorisation session and interdomain security context management, simple delegation, conditional authorisation decisions, and policy obligations handling.

  • extending xacml authorisation model to support policy obligations handling in distributed application
    Middleware for Grid Computing, 2008
    Co-Authors: Yuri Demchenko, Cees De Laat, O Koeroo, Hakon Sagehaug
    Abstract:

    The paper summarises the recent developments and discussions in the Grid and Networking security community to build interoperable and scalable authorisation infrastructure for distributed applications. The paper provides a short overview of the XACML policy format and policy obligations definition in the XACML specification. The paper analyses the basic use cases for obligations in computer Grids and on-demand Network Resource provisioning abstracted to the general complex Resource provisioning (CRP) model to identify major requirements and functionalities in obligations handling that further is proposed as a Reference Model for Obligations Handling (OHRM). The paper refers to ongoing implementations of the policy obligations interoperability and handling framework in such project as EU funded projects EGEE and Phosphorus and the proposed XACML policy and attributes profiles for Grid and Network Resource provisioning.

  • authorisation infrastructure for on demand Network Resource provisioning
    Grid Computing, 2008
    Co-Authors: Yuri Demchenko, Mihai Cristea, Cees De Laat
    Abstract:

    High performance Grid applications require high speed Network infrastructure that should be capable to provide Network connectivity service on-demand. This paper presents results of the development of the Authorisation (AuthZ) infrastructure for on-demand multidomain Network Resource provisioning (NRP). We propose a general Complex Resource Provisioning (CRP) model that can be used as a basis for AuthZ infrastructure development providing a common abstraction for provisioning both Network and Grid Resources. This model allows common policy expressions, using single user sign-on credentials when requesting and accessing complex Grid-Network Resources. The implementation described is based on the generic AAA Authorisation Framework (GAAA-AuthZ) and suggests a number of security mechanisms and components that extends GAAA-AuthZ to achieve consistent policy enforcement and security context management: Token Validation Service (TVS), AuthZ ticket used for AuthZ session management, a special XACML profile for NRP, reference model for policy obligations handling (OHRM). The proposed infrastructure and solutions are being implemented in the framework of the EU project Phosphorus and use authors experiences gained from the major Grid based and Grid oriented projects.

Zhiquan Luo - One of the best experts on this subject based on the ideXlab platform.

  • data driven adaptive Network Resource slicing for multi tenant Networks
    International Conference on Acoustics Speech and Signal Processing, 2021
    Co-Authors: Navid Reyhanian, Hamid Farmanbar, Zhiquan Luo
    Abstract:

    Network slicing to support multi-tenancy plays a key role in improving the performance of 5G Networks. In this paper, we propose a novel framework for Network slicing with the goal of maximizing the expected utilities of tenants in the backhaul and Radio Access Network (RAN), where we reconfigure slices according to the time-varying user traffic and channel states. Upon the arrival of new statistics from users and channels and considering the expected utility from serving users of a slice and the reconfiguration cost, we formulate a sparse optimization problem to reconfigure Resources for Network slices with the maximum isolation of reserved Resources. The formulated optimization is non-convex and difficult to solve. We use the group LASSO regularization and successive upper-bound minimization techniques to solve this problem by iteratively solving a sequence of convex approximations of the original problem. Simulation results verify that our approach outperforms the existing state of the art method.

H H Chen - One of the best experts on this subject based on the ideXlab platform.

  • A Multimedia Quality-Driven Network Resource Management Architecture for Wireless Sensor Networks With Stream Authentication
    Ieee Transactions on Multimedia, 2010
    Co-Authors: Weizhe Wang, D M Peng, Husayn El Sharif, H. -g. Wang, H H Chen
    Abstract:

    Media integrity, transmission quality, and energy efficiency are critical for secure wireless image streaming in a wireless multimedia sensor Network (WMSN). However, conventional data authentication and Resource allocation schemes cannot be applied directly to WMSN due to the constraints on limited energy and computing Resources. In this paper, we propose a quality-driven scheme to optimize stream authentication and unequal error protection (UEP) jointly. This scheme can provide digital image authentication, image transmission quality optimization, and high energy efficiency for WMSN. The contribution of this research is two-fold as summarized below. First, a new Resource allocationaware greedy stream authentication approach is proposed to simplify the authentication process. Second, an authentication-aware wireless Network Resource allocation scheme is developed to reduce image distortion and energy consumption in transmission. The scheme is studied by unequally protected image packets with the consideration of coding and authentication dependency. Simulation results demonstrate that the proposed scheme achieves a performance gain of 3 similar to 5 dB in terms of authenticated image distortion.

Mohsen Guizani - One of the best experts on this subject based on the ideXlab platform.

  • 5g vehicular Network Resource management for improving radio access through machine learning
    IEEE Access, 2020
    Co-Authors: Sahrish Khan, Hasan Ali Khattak, Ahmad Almogren, Munam Ali Shah, Ikram Ud Din, Ibrahim Alkhalifa, Mohsen Guizani
    Abstract:

    The current cellular technology and vehicular Networks cannot satisfy the mighty strides of vehicular Network demands. Resource management has become a complex and challenging objective to gain expected outcomes in a vehicular environment. The 5G cellular Network promises to provide ultra-high-speed, reduced delay, and reliable communications. The development of new technologies such as the Network function virtualization (NFV) and software defined Networking (SDN) are critical enabling technologies leveraging 5G. The SDN-based 5G Network can provide an excellent platform for autonomous vehicles because SDN offers open programmability and flexibility for new services incorporation. This separation of control and data planes enables centralized and efficient management of Resources in a very optimized and secure manner by having a global overview of the whole Network. The SDN also provides flexibility in communication administration and Resource management, which are of critical importance when considering the ad-hoc nature of vehicular Network infrastructures, in terms of safety, privacy, and security, in vehicular Network environments. In addition, it promises the overall improved performance. In this paper, we propose a flow-based policy framework on the basis of two tiers virtualization for vehicular Networks using SDNs. The vehicle to vehicle (V2V) communication is quite possible with wireless virtualization where different radio Resources are allocated to V2V communications based on the flow classification, i.e., safety-related flow or non-safety flows, and the controller is responsible for managing the overall vehicular environment and V2X communications. The motivation behind this study is to implement a machine learning-enabled architecture to cater the sophisticated demands of modern vehicular Internet infrastructures. The inclination towards robust communications in 5G-enabled Networks has made it somewhat tricky to manage Network slicing efficiently. This paper also presents a proof of concept for leveraging machine learning-enabled Resource classification and management through experimental evaluation of special-purpose testbed established in custom mininet setup. Furthermore, the results have been evaluated using Long Short-Term Memory (LSTM), Convolutional Neural Network (CNN), and Deep Neural Network (DNN). While concluding the paper, it is shown that the LSTM has outperformed the rest of classification techniques with promising results.

Yuri Demchenko - One of the best experts on this subject based on the ideXlab platform.

  • xacml policy profile for multidomain Network Resource provisioning and supporting authorisation infrastructure
    IEEE International Symposium on Policies for Distributed Systems and Networks, 2009
    Co-Authors: Yuri Demchenko, Mihai Cristea, Cees De Laat
    Abstract:

    Policy definition is an important component of the consistent authorisation service infrastructure that could be effectively integrated with the general Resource provisioning workflow and Network control and management plane. The paper describes the proposed XACML-NRP policy and attributes profile for Network Resource Provisioning. In addition to specifying a set of subject, Resource, action attributes that are required for consistent XACML policy definition, the proposed profile allows also handling Network path information what is especially important for QoS enforcement. To overcome stateless character of XACML policies, the proposed authorisation infrastructure provides a number of security mechanisms to support such important for NRP functionality as authorisation session and interdomain security context management, simple delegation, conditional authorisation decisions, and policy obligations handling.

  • extending xacml authorisation model to support policy obligations handling in distributed application
    Middleware for Grid Computing, 2008
    Co-Authors: Yuri Demchenko, Cees De Laat, O Koeroo, Hakon Sagehaug
    Abstract:

    The paper summarises the recent developments and discussions in the Grid and Networking security community to build interoperable and scalable authorisation infrastructure for distributed applications. The paper provides a short overview of the XACML policy format and policy obligations definition in the XACML specification. The paper analyses the basic use cases for obligations in computer Grids and on-demand Network Resource provisioning abstracted to the general complex Resource provisioning (CRP) model to identify major requirements and functionalities in obligations handling that further is proposed as a Reference Model for Obligations Handling (OHRM). The paper refers to ongoing implementations of the policy obligations interoperability and handling framework in such project as EU funded projects EGEE and Phosphorus and the proposed XACML policy and attributes profiles for Grid and Network Resource provisioning.

  • authorisation infrastructure for on demand Network Resource provisioning
    Grid Computing, 2008
    Co-Authors: Yuri Demchenko, Mihai Cristea, Cees De Laat
    Abstract:

    High performance Grid applications require high speed Network infrastructure that should be capable to provide Network connectivity service on-demand. This paper presents results of the development of the Authorisation (AuthZ) infrastructure for on-demand multidomain Network Resource provisioning (NRP). We propose a general Complex Resource Provisioning (CRP) model that can be used as a basis for AuthZ infrastructure development providing a common abstraction for provisioning both Network and Grid Resources. This model allows common policy expressions, using single user sign-on credentials when requesting and accessing complex Grid-Network Resources. The implementation described is based on the generic AAA Authorisation Framework (GAAA-AuthZ) and suggests a number of security mechanisms and components that extends GAAA-AuthZ to achieve consistent policy enforcement and security context management: Token Validation Service (TVS), AuthZ ticket used for AuthZ session management, a special XACML profile for NRP, reference model for policy obligations handling (OHRM). The proposed infrastructure and solutions are being implemented in the framework of the EU project Phosphorus and use authors experiences gained from the major Grid based and Grid oriented projects.