首页> 外文会议>IFIP/IEEE Symposium on Integrated Network and Service Management >Multi-party authorization and conflict mediation for decentralized configuration management processes
【24h】

Multi-party authorization and conflict mediation for decentralized configuration management processes

机译:用于分散式配置管理流程的多方授权和冲突中介

获取原文

摘要

Configuration management in networks with highest security demands must not depend on just one administrator and her device. Otherwise, problems can be caused by mistakes or malicious behavior of this admin, or when her computer got com-promised, which allows an attacker to abuse the administrator's far-reaching permissions.Instead, we propose to use a reliable and resilient configuration management process orchestrated by a configuration management system (CMS). This can be achieved by separation of concerns (proposing a configuration vs. authorizing it), employing multi-party authorization (MPA), and enforcing that only authorized configurations can be deployed. This results in a configuration management process that is decentralized on a human, decision-making level, and a technical, device level.However, due to different opinions or adversarial interference, the result of an MPA process can end in a conflict. This raises the question how such conflicts can be mediated in a better way than just employing majority voting, which is insufficient in certain situations. As an alternative, this paper introduces building blocks of customizable conflict mediation strategies which we integrated into our CMS TANCS [1]. The conflict mediation functionality as well as the initial TANCS implementation run on top of the distributed ledger and smart contract framework Hyperledger Fabric which makes all processes resilient and tamper-resistant.
机译:具有最高安全性要求的网络中的配置管理不能仅依赖于一个管理员及其设备。否则,此管理员的错误或恶意行为可能会导致问题,或者当她的计算机受到威胁时,这可能会导致攻击者滥用管理员的深远权限,因此,我们建议使用可靠且有弹性的配置管理过程由配置管理系统(CMS)协调。这可以通过以下方式实现:分离关注点(提出配置与授权配置),采用多方授权(MPA)并强制仅可以部署授权的配置。这导致配置管理过程分散在人员决策层和技术设备层上。但是,由于意见分歧或对抗性干扰,MPA过程的结果可能会以冲突结束。这就提出了一个问题,即与仅仅采用多数表决相比,如何以更好的方式解决这种冲突,在某些情况下这是不够的。作为替代方案,本文介绍了可定制的冲突调解策略的构建模块,这些策略已集成到CMS TANCS [1]中。冲突调解功能以及最初的TANCS实施都在分布式分类帐和智能合约框架Hyperledger Fabric之上运行,该框架使所有流程都具有弹性和防篡改性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号