%% You should probably cite draft-you-i2nsf-user-group-based-policy-02 instead of this revision. @techreport{you-i2nsf-user-group-based-policy-00, number = {draft-you-i2nsf-user-group-based-policy-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-you-i2nsf-user-group-based-policy/00/}, author = {Jianjie You and Myo Zarny and Christian Jacquenet and Mohamed Boucadair and Yizhou Li and Sumandra Majee}, title = {{User-group-based Security Policy for Service Layer}}, pagetotal = 15, year = 2015, month = oct, day = 19, abstract = {This draft discusses the User-group Aware Policy Control (UAPC) framework that facilitates consistent enforcement of security policies based on user group identity. The framework calls for: (1) a user-group identifier derived from predefined policy criteria (e.g., source IP, time-of-day, device certificate, etc.) for security policy enforcement; (2) a logical policy server that maintains user- group identification policies as well as inter-user-group permission policies; and (3) a logical security controller responsible for managing Network Security Functions (NSFs), and implementing necessary policies on them. The document discusses key northbound APIs of the framework that fall within the scope of the I2NSF Service Layer.}, }