首页> 外文会议>IEEE International Conference on Hot Information-Centric Networking >CDAC: A Collaborative Data Access Control Scheme in Named Data Networking
【24h】

CDAC: A Collaborative Data Access Control Scheme in Named Data Networking

机译:CDAC:命名数据网络的协作数据访问控制方案

获取原文

摘要

Named Data Networking (NDN) shifts networking paradigm from host-oriented to data-oriented and supports in-network caching. However, in-network caching brings about some new security issues (e.g., the separation of ownership and management of data). In native NDN architecture, consumers' requests are usually authenticated by a content producer, which results in highly computation overhead and unnecessary network delay. Moreover, in such a scenario where the connection between content producer and network is intermittent, encrypted contents cached in routers fail to be accessed by consumers due to lacking of content producer's permission. In this paper, we propose a collaborative data access control scheme for NDN, called CDAC, in which data access control is performed at cached-enabled routers rather than single content producer. In addition, enhanced secret sharing method is applied to achieve data access control in the situation where the connection between content producer and network is intermittent. We also use two-variable one-way function to reduce the computation overhead caused by consumer's revocation. Through reasonable security analysis and the comparison with preliminary works, the CDAC scheme achieves the expected design goals. The experimental results demonstrate that our scheme is efficient for N DN architecture, and introduces slight delay for contents securely retrieval.
机译:命名联网从范例数据网络(NDN)移位主机为导向,以面向数据的和支持在网络缓存。然而,在网络缓存带来了一些新的安全问题(例如,所有权和数据管理的分离)。在本地NDN架构,消费者的要求通常是由内容制作,认证其结果在高度计算开销和不必要的网络延迟。此外,在这样的情形,其中内容制作和网络之间的连接被间歇性的,在路由器的缓存加密的内容不能被消费者由于缺乏内容制作者的许可的访问。在本文中,我们提出了NDN协作数据访问控制方案,称为CDAC,其中数据访问控制是在启用缓存的路由器,而不是单一的内容制作商进行。此外,增强的秘密共享方法应用于在内容制作者和网络之间的连接是间断的情况来实现数据的访问控制。我们还使用双变量单向函数,以减少消费者的开销撤销导致了计算。通过合理的安全分析,并与前期作品相比,华助会计划达到了预期的设计目标。实验结果表明,我们的方案是有效的N个DN架构,并引入了内容安全检索轻微的延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号