...
首页> 外文期刊>Computer networks >Design and implementation of a confidentiality and access control solution for publish/subscribe systems
【24h】

Design and implementation of a confidentiality and access control solution for publish/subscribe systems

机译:设计/实现发布/订阅系统的机密性和访问控制解决方案

获取原文
获取原文并翻译 | 示例
           

摘要

The publish/subscribe model offers a loosely-coupled communication paradigm where applications interact indirectly and asynchronously. Publishers generate events that are sent to interested applications through a network of brokers. Subscribers express their interest by specifying filters that brokers can use for routing the events. Supporting confidentiality of messages being exchanged is still challenging. First of all, it is desirable that any scheme used for protecting the confidentiality of both the events and filters should not require publishers and subscribers to share secret keys. In fact, such a restriction is against the loose-coupling of the model. Moreover, such a scheme should not restrict the expressiveness of filters and should allow the broker to perform event filtering to route the events to the interested parties. Existing solutions do not fully address these issues. In this paper, we provide a novel scheme that supports (ⅰ) confidentiality for events and filters; (ⅱ) allows publishers to express further constraints about who can access their events; (ⅲ) filters that can express very complex constraints on events even if brokers are not able to access any information in clear on both events and filters; (ⅳ) and, finally, it does not require publishers and subscribers to share keys. Furthermore, we show how we applied our scheme to a real-world e-health scenario, developed together with a hospital. We also describe the implementation of our solution in Java and the integration with an existing publish/subscribe system.
机译:发布/订阅模型提供了一种松耦合的通信范例,其中应用程序间接和异步地交互。发布者生成事件,这些事件通过代理人网络发送到感兴趣的应用程序。订阅者通过指定代理可用于路由事件的筛选器来表达其兴趣。支持所交换消息的机密性仍然是一个挑战。首先,希望用于保护事件和过滤器的机密性的任何方案都不应要求发布者和订阅者共享秘密密钥。实际上,这种限制不利于模型的松耦合。此外,这种方案不应限制过滤器的表达,而应允许代理执行事件过滤以将事件路由到感兴趣的各方。现有的解决方案不能完全解决这些问题。在本文中,我们提供了一种新颖的方案,该方案支持(ⅰ)事件和过滤器的机密性; (ⅱ)允许发布者对谁可以访问其事件发表进一步的限制; (ⅲ)过滤器可以对事件表达非常复杂的约束,即使经纪人无法同时访问事件和过滤器中的任何信息; (ⅳ),最后,它不需要发布者和订阅者共享密钥。此外,我们展示了如何将我们的计划应用于与医院一起开发的现实世界电子医疗场景。我们还将描述我们的解决方案在Java中的实现以及与现有发布/订阅系统的集成。

著录项

  • 来源
    《Computer networks》 |2012年第7期|2014-2037|共24页
  • 作者单位

    CREATE-NET international Research Center, Via alia Cascata 56 D, 38123 Trento, Italy;

    CREATE-NET international Research Center, Via alia Cascata 56 D, 38123 Trento, Italy,Department of Computer Science, University of Auckland, Private Bag 92019, Auckland 1142, New Zealand;

    Department of Information Engineering and Computer Science, University of Trento, Trento, Italy;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Publish/subscribe; Confidentiality; Attribute-based encryption; Encrypted search;

    机译:发布/订阅;保密;基于属性的加密;加密搜寻;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号