首页> 外文会议>International Conferece For Internet Technology And Secured Transactions >Issues in inter-organisational encryption systems: The problem with FedLink
【24h】

Issues in inter-organisational encryption systems: The problem with FedLink

机译:组织间加密系统中的问题:FEDLINK的问题

获取原文

摘要

Organisations look towards encryption and Virtual Private Networks (VPNs) as the solution to a range of business requirements. Often, this involves the protection of internal traffic in transit between different locations. However it can also be used as a means of securely exchanging information with business partners. As inter-organisational encryption systems scale to accommodate larger numbers of participants, a number of challenges arise in maintaining reliability and scalability whilst also preserving the security of the system. In some cases these inter-organisational VPNs may involve hosts such as mail relays that also interact with other mail relays on the Internet external to the encryption or VPN service. In such circumstances, there are several attack vectors other than exploits against encryption or authentication components which may be used to cause sensitive traffic to either be erroneously forwarded without being encrypted, or forwarded to the incorrect encryption/VPN peer. This paper examines one of the security issues that can occur in such an architecture; the requirement that other application or system dependencies such as DNS are themselves appropriately secured. It describes how this issue manifests in the ‘FedLink’ inter-organisational encryption system deployed within the Australian Federal Government. It assesses how well some techniques such as DNSSec might mitigate the issues described and proposes other controls that could reduce the risk of information leakage. The proposed controls involve leveraging existing device capabilities and existing policy requirements. This makes the application of the controls both cost-effective and reasonably achievable. The controls also have minimal configuration overhead once implemented, meaning that the overall system retains its existing scalability characteristics.
机译:组织将向加密和虚拟专用网络(VPN)视为一系列业务要求的解决方案。通常,这涉及在不同地点之间的运输中保护内部交通。然而,它也可以用作与商业伙伴安全地交换信息的手段。作为组织间加密系统规模以适应更多的参与者,在维持可靠性和可扩展性时出现了许多挑战,同时保留了系统的安全性。在某些情况下,这些组织间VPN可能涉及诸如邮件继电器的主机,这些邮件继电器也与加密或VPN服务外部的Internet上的其他邮件继电器交互。在这种情况下,除了用于对加密或认证组件之外的攻击载体之外存在若干攻击载体,该组件可用于导致敏感流量以错误地转发而不被加密,或转发到不正确的加密/ VPN对等体。本文研究了这种架构中可能发生的安全问题之一;要求其他应用程序或系统依赖性如DNS本身适当地保护。它描述了这个问题在&#x2018中的这个问题; fedlink’组织间加密系统部署在澳大利亚联邦政府内。它评估了某些技术(如DNSSEC)可能减轻所描述的问题,并提出了可能降低信息泄漏风险的其他控件。建议的控制涉及利用现有的设备能力和现有的政策要求。这使得控件的应用成本有效和合理可取。该控件还实现了一旦实现的配置开销也具有最小的配置,这意味着整个系统保留其现有的可扩展性特性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号