CertRevoke: a certificate revocation framework for named data networking

CertRevoke: a certificate revocation framework for named data networking
复制标题

DOI:
10.1145/3517212.3558079
复制
发表时间:
2022-09
期刊:
Proceedings of the 9th ACM Conference on Information-Centric Networking
影响因子:
--
通讯作者:
Tianyuan Yu;Hongcheng Xie;Siqi Liu;Xinyv Ma;X. Jia;Lixia Zhang
Tianyuan Yu;Hongcheng Xie;Siqi Liu;Xinyv Ma;X. Jia;Lixia Zhang
中科院分区:
其他
文献类型:
--
作者:
Tianyuan Yu;Hongcheng Xie;Siqi Liu;Xinyv Ma;X. Jia;Lixia Zhang

文献摘要

被引文献

相似文献

命名数据网络(NDN)通过要求所有数据包在生产时签名来保护网络通信。这一要求使得可用和高效的NDN证书颁发和撤销对于NDN操作至关重要。本文首先研究并阐明与NDN证书撤销相关的核心概念,然后继续设计NDN证书撤销框架CertRevoke。CertRevoke利用命名约定和信任模式来确保证书所有者和颁发者合法地为已撤销的证书生成网络内可缓存的记录。我们通过案例研究来评估CertRevoke的安全属性和性能。我们的研究结果表明,部署CertRevoke在一个可操作的NDN网络是可行的。
Named Data Networking (NDN) secures network communications by requiring all data packets to be signed upon production. This requirement makes usable and efficient NDN certificate issuance and revocation essential for NDN operations. In this paper, we first investigate and clarify core concepts related to NDN certificate revocation, then proceed with the design of CertRevoke, an NDN certificate revocation framework. CertRevoke utilizes naming conventions and trust schema to ensure certificate owners and issuers legitimately produce in-network cacheable records for revoked certificates. We evaluate the security properties and performance of CertRevoke through case studies. Our results show that deploying CertRevoke in an operational NDN network is feasible.