首页> 外文会议>International Conference on Computer Communication and Networks >Pervasive Internet-Wide Low-Latency Authentication
【24h】

Pervasive Internet-Wide Low-Latency Authentication

机译:普遍的互联网范围的低延迟身份验证

获取原文

摘要

In a world with increasing simplicity to store, transfer, and analyze large volumes of data, it becomes more and more important that data confidentiality and integrity be preserved in transit by default. Unfortunately, a large security gap exists between unprotected or low-security communication, such as opportunistic encryption and trust-on-first-use (TOFU) security, and high-security communication, such as TLS using server certificates or DNSSEC. Our goal is to reduce this gap and achieve a base layer for authentication and secrecy that is strictly better than TOFU security. We achieve this by designing PILA, a novel authentication method with dynamic trust anchors, which leverages irrefutable cryptographic proof of misbehavior to incentivize benign behavior. We implement PILA extensions for SSH, TLS, and DNS and show that the overhead for a typical SSH and TLS connection establishment is negligible, and that PILA only causes a marginal processing overhead of $sim 100 mu mathrm{s}$ per DNS response at the endpoints.
机译:在一个世界上越来越简单地存储,传输和分析大量数据,它变得越来越重要,默认情况下,数据机密性和完整性被保留在运输过程中。遗憾的是,不受保护或低安全通信之间存在大的安全缺口,例如机会主义的加密和授予首先使用(Tofu)安全性和高安全性通信,例如使用服务器证书或DNSSEC的TLS。我们的目标是减少这种差距,并实现了一个用于身份验证和保密的基础层,这比豆腐安全性严格更好。我们通过设计Pila来实现这一目标,这是一种具有动态信任锚点的新型认证方法,它利用了不可追溯的密码证明不当行为的激励良好行为。我们为SSH,TLS和DNS实施Pila扩展,并显示典型SSH和TLS连接建立的开销可以忽略不计,并且PILA仅导致$ SIM 100 Mathrm {s} $的边际处理开销。每个DNS响应在端点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号