Token-based authorization of Connection Oriented Network resources
Leon Gommans, Franco Travostino, John Vollbrecht, C.T.A.M. de Laat, Robert Meijer · 2004
Authentication, Authorization and Accounting (AAA) mechanisms have an increasingly versatile role when performing access control on various types of network resources. Emerging data intensive grid applications generate new network requirements. These requirements call for (pre-) allocate-able data transport facilities serving specific user communities. The network specific requirements are characterized by a very limited need for connectivity, usage during specific periods and in many cases the need to span large distances at maximum available speed. This should all be possible at the lowest achievable cost involving different owners of the involved networks. Solutions are researched in the area of connection oriented networking using relative cheap, lower layer switches. This paper presents a novel usage of an existing model to grant access to connection oriented network resources based on an authorization message sequence involving a token. The presented approach makes use of specialized monitor hardware emerging in high capacity low-layer switches.