【24h】

Access control enforcement in Named Data Networking

机译:命名数据网络中的访问控制实施

获取原文

摘要

Named Data Networking (NDN) represents one of the major Information Centric Networking (ICN) candidates for future Internet architectures. It treats data as the central element and it leverages in-network caching. Access control is a fundamental security feature in this project. It limits data access to only authorized entities. However, it can no longer be tied to a content location or to a particular host, since multiple copies of a same data can reside in various network locations. Therefore, a data-oriented access control model must be adopted. In this paper, we propose an encryption-based access control scheme for NDN that allows encrypted content to freely reside anywhere in the network. This proposal represents an enhancement of the solution already implemented in the actual NDN prototype, CCNx. It is based on a new cryptographic model for access rights management and on an adaptation of the naming system. It mitigates identified attacks and it reduces the overhead cost.
机译:命名数据网络(NDN)代表了未来Internet体系结构的主要信息中心网络(ICN)候选者之一。它将数据视为中心元素,并利用网络内缓存。访问控制是此项目中的基本安全功能。它将数据访问限制为仅授权实体。但是,由于同一数据的多个副本可以驻留在各个网络位置,因此它不再可以绑定到内容位置或特定的主机。因此,必须采用面向数据的访问控制模型。在本文中,我们为NDN提出了一种基于加密的访问控制方案,该方案允许加密的内容自由地驻留在网络中的任何位置。该建议表示对实际NDN原型CCNx中已经实现的解决方案的增强。它基于用于访问权限管理的新密码模型以及命名系统的改编。它减轻了已识别的攻击,并降低了开销成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号