Identity-Based Access Control for Ad Hoc Groups

Identity-Based Access Control for Ad Hoc Groups
复制标题

DOI:
10.1007/11496618_27
复制
发表时间:
2004-12
期刊:
--
影响因子:
--
通讯作者:
Nitesh Saxena;G. Tsudik;J. Yi
Nitesh Saxena;G. Tsudik;J. Yi
中科院分区:
其他
文献类型:
--
作者:
Nitesh Saxena;G. Tsudik;J. Yi

文献摘要

被引文献

相似文献

以组为中心的计算和通信的激增激发了对提供组访问控制的机制的需求。组访问控制包括用于组成员的接纳以及撤销/驱逐的机制。特别是在诸如对等(P2P)系统和移动的自组织网络(MANN)之类的自组织组中,需要安全的组接纳来引导其他组安全服务。此外,需要安全的成员资格撤销来驱逐行为不端或恶意的成员。与集中式(例如,多播)组,自组织组以分散的方式操作,并适应动态成员资格,这使得访问控制既有趣又具有挑战性。虽然最近的一些工作取得了初步进展,至于接纳问题,成员撤销problem尚未得到解决,在本文中,我们开发了一种基于身份的组接纳控制技术,避免了以前的(基于证书的)方法的某些缺点。我们还提出了一个同伴的成员资格撤销机制。我们的解决方案是强大的,完全分布式的,可扩展的,并在同一时间,合理的效率,实验结果表明。
The proliferation of group-centric computing and communication motivates the need for mechanisms to providegroup access control. Group access control includes mechanisms for admission as well as revocation/eviction of group members. Particularly in ad hoc groups, such as peer-to-peer (P2P) systems and mobile ad hoc networks (MANETs), secure group admission is needed to bootstrap other group security services. In addition, secure membership revocation is required to evict misbehaving or malicious members. Unlike centralized (e.g., multicast) groups, ad hoc groups operate in a decentralized manner and accommodate dynamic membership which make access control both interesting and challenging. Although some recent work made initial progress as far as the admission problem, the membership revocation problem has not been addressed.In this paper, we develop an identity-based group admission control technique which avoids certain drawbacks of previous (certificate-based) approaches. We also propose a companion membership revocation mechanism. Our solutions are robust, fully distributed, scalable and, at the same time, reasonably efficient, as demonstrated by the experimental results.