首页> 外文会议>Unmanned Systems Technology Conference >Protecting Publish/Subscribe Interactions via TLS and a System-Wide Certificate Validation Engine
【24h】

Protecting Publish/Subscribe Interactions via TLS and a System-Wide Certificate Validation Engine

机译:通过TLS和系统范围的证书验证引擎保护发布/订阅交互

获取原文

摘要

Multiple defense-relevant open architecture standards include the publish/subscribe messaging paradigm, which allows for dynamic network topology and scalability. Using the Transport Layer Security (TLS) protocol to secure such messaging is common; however, certificate validation must be performed. Typically, certificate validation is left to the application to configure, but history has shown that application developers often get incorrect certificate validation. In this paper, we explore the overhead costs of different security implementations under varying network conditions within a pub/sub system. Furthermore, we study how TrustBase strengthens and simplifies certificate validation within a pub/sub architecture. TrustBase allows a systemadrninistratororintegratorto specify a single certificate validation policy forall applications in the system. This ensures that even if application developers have misconfigured certificate validation, the policy is followed, which we believe could make systemaccreditation easier. Our study is conducted on a notional system with an Apache ActiveMQ messaging server. Handshake timing data are collected from several publishers and subscribers to understand theoverheadresultingfromusing TLS with and without the TrustBase kernel module active on the system Our experiments run with different certificate validation strategies including prepositioned public-keys and certificate chaining with a trus ted rootcertificate authority. To our knowledge, we are the first to study TrustBase in an environment that emulates realistic networkconditions and a messaging paradigm beyond the traditional client/server model. Ourresults confirm those of the original TrustBase work; TrustBase adds negligible overhead and is easily configurable as a universal certificate validation authority.
机译:多个与国防相关的开放架构标准包括发布/订阅消息传递范例,该范例允许动态网络拓扑和可伸缩性。通常使用传输层安全性(TLS)协议来保护此类消息传递;但是,必须执行证书验证。通常,证书验证由应用程序配置,但是历史记录表明,应用程序开发人员经常会获得不正确的证书验证。在本文中,我们探索了发布/订阅系统中不同网络条件下不同安全实现的开销成本。此外,我们研究了TrustBase如何增强和简化发布/订阅体系结构中的证书验证。 TrustBase允许系统管理员或集成商为系统中的所有应用程序指定单个证书验证策略。这样可以确保即使应用程序开发人员配置了错误的证书验证,也可以遵循该策略,我们认为该策略可以使系统认证更加容易。我们的研究是在带有Apache ActiveMQ消息传递服务器的概念系统上进行的。从多个发布者和订阅者处收集握手时序数据,以了解在系统上是否启用TrustBase内核模块的情况下使用TLS并使用TLS所产生的开销。我们的实验使用不同的证书验证策略进行操作,包括预置的公钥和具有根证书颁发机构的证书链。据我们所知,我们是第一个在模拟现实网络条件和超越传统客户端/服务器模型的消息传递范式的环境中研究TrustBase的公司。我们的结果证实了TrustBase原始工作的结果; TrustBase增加的开销可以忽略不计,并且可以轻松配置为通用证书验证机构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号