首页> 外文会议>IEEE International Conference on Communications >Achieving secure and scalable data access control in information-centric networking
【24h】

Achieving secure and scalable data access control in information-centric networking

机译:在以信息为中心的网络中实现安全且可扩展的数据访问控制

获取原文

摘要

Shifting from host-oriented to data-oriented, information-centric networking (ICN) adopts several key design principles, e.g., in-network caching, to cope with the tremendous internet growth. In the ICN setting, data to be distributed can be cached by ICN routers anywhere and accessed arbitrarily by customers without data publishers' permission, which imposes new challenges when achieving data access control: (i) security: How can data publishers protect data confidentiality (either data cached by ICN routers or data accessed by authorized users) even when an authorized user's decryption key was revoked or compromised, and (ii) scalability: How can data publishers leverage ICN's promising features and enforce access control without complicated key management or extensive communication. This paper addresses these challenges by using the new proposed dual-phase encryption that uniquely combines the ideas from one-time decryption key, proxy re-encryption and all-or-nothing transformation, while still being able to leverage ICN's features. Our analysis and performance show that our solution is highly efficient and provable secure under the existing security model.
机译:从以主机为中心转变为以数据为中心的以信息为中心的网络(ICN)采用了一些关键设计原则,例如,网络内缓存,以应对互联网的巨大增长。在ICN设置中,要分发的数据可以由ICN路由器缓存到任何地方,并可以在未经数据发布者许可的情况下由客户任意访问,这在实现数据访问控制时提出了新的挑战:(i)安全性:数据发布者如何保护数据机密性( (即使是已撤销或损害授权用户的解密密钥的情况,也可能是由ICN路由器缓存的数据或由授权用户访问的数据),以及(ii)可伸缩性:数据发布者如何在不进行复杂密钥管理或广泛通信的情况下利用ICN的有前途的功能并实施访问控制。本文通过使用新提出的双阶段加密解决了这些挑战,该双阶段加密将一次性解密密钥,代理重新加密和全有或无转换的思想独特地结合在一起,同时仍然能够利用ICN的功能。我们的分析和性能表明,在现有安全模型下,我们的解决方案是高效且可证明的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号