首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >A Policy Enforcing Mechanism for Trusted Ad Hoc Networks
【24h】

A Policy Enforcing Mechanism for Trusted Ad Hoc Networks

机译:可信Ad Hoc网络的策略执行机制

获取原文
获取原文并翻译 | 示例

摘要

To ensure fair and secure communication in Mobile Ad hoc Networks (MANETs), the applications running in these networks must be regulated by proper communication policies. However, enforcing policies in MANETs is challenging because they lack the infrastructure and trusted entities encountered in traditional distributed systems. This paper presents the design and implementation of a policy enforcing mechanism based on Satem, a kernel-level trusted execution monitor built on top of the Trusted Platform Module. Under this mechanism, each application or protocol has an associated policy. Two instances of an application running on different nodes may engage in communication only if these nodes enforce the same set of policies for both the application and the underlying protocols used by the application. In this way, nodes can form trusted application-centric networks. Before allowing a node to join such a network, Satem verifies its trustworthiness of enforcing the required set of policies. Furthermore, Satem protects the policies and the software enforcing these policies from being tampered with. If any of them is compromised, Satem disconnects the node from the network. We demonstrate the correctness of our solution through security analysis, and its low overhead through performance evaluation of two MANET applications.
机译:为了确保在移动自组织网络(MANET)中进行公平和安全的通信,必须通过适当的通信策略来管理在这些网络中运行的应用程序。但是,在MANET中执行策略具有挑战性,因为它们缺乏传统分布式系统中遇到的基础结构和受信任的实体。本文介绍了基于Satem的策略执行机制的设计和实现,Satem是在可信平台模块之上构建的内核级可信执行监视器。在这种机制下,每个应用程序或协议都有一个关联的策略。仅当这些节点对应用程序和应用程序使用的基础协议都强制执行相同的策略集时,在不同节点上运行的应用程序的两个实例才可以参与通信。这样,节点可以形成以应用程序为中心的可信网络。在允许节点加入这样的网络之前,Satem会验证其执行必要策略集的可信度。此外,Satem保护策略和实施这些策略的软件不被篡改。如果其中任何一个受到威胁,则Satem会将节点与网络断开连接。我们通过安全性分析证明了我们解决方案的正确性,并通过两个MANET应用程序的性能评估证明了其低开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号