Identity-Based Access Control for Ad Hoc Groups
Identity-Based Access Control for Ad Hoc Groups
复制标题
DOI:
10.1007/11496618_27
复制
发表时间:
2004-12
期刊:
影响因子:
--
通讯作者:
Nitesh Saxena;G. Tsudik;J. Yi
中科院分区:
文献类型:
--
作者:
Nitesh Saxena;G. Tsudik;J. Yi
The proliferation of group-centric computing and communication motivates the need for mechanisms to providegroup access control. Group access control includes mechanisms for admission as well as revocation/eviction of group members. Particularly in ad hoc groups, such as peer-to-peer (P2P) systems and mobile ad hoc networks (MANETs), secure group admission is needed to bootstrap other group security services. In addition, secure membership revocation is required to evict misbehaving or malicious members. Unlike centralized (e.g., multicast) groups, ad hoc groups operate in a decentralized manner and accommodate dynamic membership which make access control both interesting and challenging. Although some recent work made initial progress as far as the admission problem, the membership revocation problem has not been addressed.In this paper, we develop an identity-based group admission control technique which avoids certain drawbacks of previous (certificate-based) approaches. We also propose a companion membership revocation mechanism. Our solutions are robust, fully distributed, scalable and, at the same time, reasonably efficient, as demonstrated by the experimental results.