This paper concentrates on one particular aspect of providing communication security: rewalls between domains of trust. We argue that signaling support for providing scalable security services is a design requirement. On this basis we outline a reference model for rewall technology. It captures the current state of the art and proves suitable for connection-oriented high-performance networks. The architecture is an improvement in network management and provides a controlled exposure of the internal network structure to the outside, and transparency to the user. Its components are endpoint authentication, call admission control, connection authentication, audit, and a distributed architecture with centralized policy. The paper discusses implications of this reference model for the design of signaling protocols.
Christoph L. Schuba, Eugene H. Spafford