<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>27</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Gianni De Rosa</style></author><author><style face="normal" font="default" size="100%">Stefano Pentassuglia</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Specification of mPlane Access Control and Data Protection Mechanisms</style></title></titles><keywords><keyword><style  face="normal" font="default" size="100%">access control</style></keyword><keyword><style  face="normal" font="default" size="100%">anonymisation</style></keyword><keyword><style  face="normal" font="default" size="100%">authentication plane</style></keyword><keyword><style  face="normal" font="default" size="100%">privacy</style></keyword><keyword><style  face="normal" font="default" size="100%">security</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2013</style></year><pub-dates><date><style  face="normal" font="default" size="100%">08/2013</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">D1.2</style></number><publisher><style face="normal" font="default" size="100%">mPlane Consortium</style></publisher><pub-location><style face="normal" font="default" size="100%">Torino</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;This document primarily defines security specifications for the mPlane architecture (in terms of authentication, access control and safe communications), on the basis of what specified in the D1.1. Also, it provides a description of the measures that can be adopted in order to guarantee the privacy of the data gathered through the probes. This aspect of the mPlane infrastructure must not be neglected, since from a legal point of view the users' right to privacy must be protected in any case. The techniques to be adopted are anonymization and aggregation, but utility of data decreases as the level of privacy increases, hence it is necessary to find a good trade-off. Two protocols are proposed for secure communications among components: TLS and SSH, which adopt respectively X.509 certificates and RSA keys for identity management. As the access control policy that will be adopted depends mostly on the mPlane administrators' choices, this document provides a survey of several approaches. The cross-domain and the mobile scenarios are also analyzed, providing solutions that can guarantee access control, security and privacy.&lt;/p&gt;</style></abstract><work-type><style face="normal" font="default" size="100%">Public Deliverable</style></work-type></record></records></xml>