首页> 外文OA文献 >Interest-Based Access Control for Content Centric Networks (extended version)
【2h】

Interest-Based Access Control for Content Centric Networks (extended version)

机译:基于兴趣的内容中心网络访问控制(扩展   版)

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Content-Centric Networking (CCN) is an emerging network architecture designedto overcome limitations of the current IP-based Internet. One of thefundamental tenets of CCN is that data, or content, is a named and addressableentity in the network. Consumers request content by issuing interest messageswith the desired content name. These interests are forwarded by routers toproducers, and the resulting content object is returned and optionally cachedat each router along the path. In-network caching makes it difficult to enforceaccess control policies on sensitive content outside of the producer sincerouters only use interest information for forwarding decisions. To that end, wepropose an Interest-Based Access Control (IBAC) scheme that enables accesscontrol enforcement using only information contained in interest messages,i.e., by making sensitive content names unpredictable to unauthorized parties.Our IBAC scheme supports both hash- and encryption-based name obfuscation. Weaddress the problem of interest replay attacks by formulating a mutual trustframework between producers and consumers that enables routers to performauthorization checks when satisfying interests from their cache. We assess thecomputational, storage, and bandwidth overhead of each IBAC variant. Our designis flexible and allows producers to arbitrarily specify and enforce any type ofaccess control on content, without having to deal with the problems of contentencryption and key distribution. This is the first comprehensive design for CCNaccess control using only information contained in interest messages.
机译:以内容为中心的网络(CCN)是一种新兴的网络体系结构,旨在克服当前基于IP的Internet的局限性。 CCN的基本原则之一是数据或内容是网络中的命名实体和可寻址实体。消费者通过发布带有所需内容名称的兴趣消息来请求内容。这些兴趣由路由器转发给生产者,然后返回结果内容对象,并可选地沿路径将其缓存在每个路由器上。网络内缓存使在生产者外部的敏感内容上实施访问控制策略变得困难,因为路由器仅将兴趣信息用于转发决策。为此,我们提出了一种基于兴趣的访问控制(IBAC)方案,该方案仅使用感兴趣消息中包含的信息即可启用访问控制,即通过使敏感内容名称无法被未经授权的参与者预测。我们的IBAC方案支持基于散列和加密的名称混淆。通过制定生产者和消费者之间的相互信任框架,使路由器在满足其缓存中的兴趣时能够执行授权检查,从而解决了兴趣重播攻击的问题。我们评估每个IBAC变体的计算,存储和带宽开销。我们的设计非常灵活,允许生产者随意指定和实施对内容的任何类型的访问控制,而不必处理内容加密和密钥分发的问题。这是仅使用兴趣消息中包含的信息进行CCN访问控制的第一个综合设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号