Towards Policy Enforcement Point as a Service (PEPS)
Arash Shaghaghi, Mohamed Ali (Dali) Kaafar, Sandra Scott-Hayward, and Salil S. Kanhere, Sanjay Jha

TL;DR
This paper introduces Policy Enforcement as a Service (PEPS), leveraging SDN architecture to enable flexible, distributed, and cooperative access control across multiple domains and layers, enhancing security and policy enforcement.
Contribution
It proposes a novel PEPS model utilizing SDN for flexible, distributed access control, and demonstrates its practical application through a prototype implementation.
Findings
PEPS enables inter-layer and inter-domain access control.
The prototype demonstrates effective location-based access control.
PEPS enhances security with a defense-in-depth approach.
Abstract
In this paper, we coin the term Policy Enforcement as a Service (PEPS), which enables the provision of innovative inter-layer and inter-domain Access Control. We leverage the architecture of Software-Defined-Network (SDN) to introduce a common network-level enforcement point, which is made available to a range of access control systems. With our PEPS model, it is possible to have a `defense in depth' protection model and drop unsuccessful access requests before engaging the data provider (e.g. a database system). Moreover, the current implementation of access control within the `trusted' perimeter of an organization is no longer a restriction so that the potential for novel, distributed and cooperative security services can be realized. We conduct an analysis of the security requirements and technical challenges for implementing Policy Enforcement as a Service. To illustrate the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Software-Defined Networks and 5G · Security and Verification in Computing
