...
首页> 外文期刊>Sustainability >Faster Data Forwarding in Content-Centric Network via Overlaid Packet Authentication Architecture
【24h】

Faster Data Forwarding in Content-Centric Network via Overlaid Packet Authentication Architecture

机译:通过覆盖的数据包认证体系结构更快地在内容中心网络中转发数据转发

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Content-Centric Networking (CCN) is one of the emerging paradigms for the future Internet, which shifts the communication paradigm from host-centric to data-centric. In CCN, contents are delivered by their unique names, and a public-key-based signature is built into data packets to verify the authenticity and integrity of the contents. To date, research has tried to accelerate the validation of the given data packets, but existing techniques were designed to improve the performance of content verification from the requester’s viewpoint. However, we need to efficiently verify the validity of data packets in each forwarding engine, since the transmission of invalid packets influences not only security but also performance, which can lead to a DDoS (Distributed Denial of Service) attack on CCN. For example, an adversary can inject a number of meaningless packets into CCN to consume the forwarding engines’ cache and network bandwidth. In this paper, a novel authentication architecture is introduced, which can support faster forwarding by accelerating the performance of data validation in forwarding engines. Since all forwarding engines verify data packets, our authentication architecture can eliminate invalid packets before they are injected into other CCN nodes. The architecture utilizes public-key based authentication algorithms to support public verifiability and non-repudiation, but a novel technique is proposed in this paper to reduce the overhead from using PKI for verifying public keys used by forwarding engines and end-users in the architecture. The main merit of this work is in improving the performance of data-forwarding in CCN regardless of the underlying public-key validation mechanism, such as PKI, by reducing the number of accesses to the mechanism. Differently from existing approaches that forgive some useful features of the Naive CCN for higher performance, the proposed technique is the only architecture which can support all useful features given by the Naive CCN.
机译:以内容为中心的网络(CCN)是未来互联网的新兴范式之一,它将通信范例从主持人传输转移到以数据为中心。在CCN中,内容通过其唯一的名称提供,并内置了基于公钥的签名,以验证内容的真实性和完整性。迄今为止,研究试图加速给定数据包的验证,但旨在从请求者的角度来提高内容验证的性能。但是,我们需要有效地验证每个转发引擎中数据包的有效性,因为无效数据包的传输不仅影响安全性,而且可能导致对CCN的DDOS(分布式拒绝服务)攻击。例如,对手可以将许多无意义的数据包注入CCN以消耗转发引擎的高速缓存和网络带宽。在本文中,引入了一种新的认证架构,可以通过加速转发引擎中的数据验证性能来支持更快的转发。由于所有转发引擎验证数据包,因此我们的身份验证架构可以在将其注入其他CCN节点之前消除无效数据包。该架构利用了基于公钥的身份验证算法来支持公共验证性和非拒绝,但是在本文中提出了一种新颖的技术,以减少使用PKI来验证转发引擎和架构中的最终用户使用的公钥的开销。这项工作的主要优点是通过减少对机制的访问数量,从而提高CCN中数据转发的性能而不管潜在的公钥验证机制,如PKI。与现有的方法不同,原谅Naive CCN的一些有用特征以获得更高的性能,所提出的技术是唯一可以支持天真CCN给出的所有有用特征的架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号