首页> 外文期刊>Journal of network and computer applications >An integrated authentication and authorization approach for the network of information architecture
【24h】

An integrated authentication and authorization approach for the network of information architecture

机译:信息架构网络的集成身份验证和授权方法

获取原文
获取原文并翻译 | 示例

摘要

Several projects propose an information centric approach to the network of the future. Such an approach makes efficient content distribution possible by making information retrieval host-independent and integration into the network storage for caching information. Requests for particular content can, thus, be satisfied by any host or server holding a copy. One well-established approach of information centric networks is the Network of Information (NetInf) architecture, developed as part of the EU FP7 project SAIL The approach is based on the Publish/Subscribe model, where hosts can join a network, publish data, and subscribe to publications. The NetInf introduces two main stages namely, the Publication and Data Retrieval through which hosts publish and retrieve data. Also, a distributed Name Resolution System (NRS) has been introduced to map the data to its publishers. The NRS is vulnerable to masquerading and content poisoning attacks through invalid data registration. Therefore, the paper proposes a Registration stage to take place before the publication and data retrieval stage. This new stage will identify and authenticate hosts before being able to access the NetInf system. Furthermore, the Registration stage uses (cap)abilities-based access policy to mitigate the issue of unauthorized access to data objects. The proposed solutions have been formally verified using formal methods approach. (C) 2014 Elsevier Ltd. All rights reserved.
机译:有几个项目提出了以信息为中心的未来网络方法。通过使信息检索独立于主机并集成到网络存储中以缓存信息,这种方法使有效的内容分发成为可能。因此,任何拥有副本的主机或服务器都可以满足对特定内容的请求。一种成熟的以信息为中心的网络方法是信息网络(NetInf)体系结构,它是EU FP7项目SAIL的一部分开发。该方法基于“发布/订阅”模型,主机可以在其中加入网络,发布数据和订阅出版物。 NetInf引入了两个主要阶段,即发布和数据检索,主机通过这些阶段来发布和检索数据。此外,已经引入了分布式名称解析系统(NRS)来将数据映射到其发布者。通过无效的数据注册,NRS容易遭受伪装和内容中毒攻击。因此,本文建议在发布和数据检索阶段之前进行注册阶段。这个新阶段将在能够访问NetInf系统之前识别并验证主机。此外,注册阶段使用基于(功能)的访问策略来减轻未经授权访问数据对象的问题。所提出的解决方案已使用形式方法正式验证。 (C)2014 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号