Disclosure control in multi-domain publish/subscribe systems

Disclosure control in multi-domain publish/subscribe systems
复制标题

DOI:
10.1145/2002259.2002283
复制
发表时间:
2011-07
期刊:
--
影响因子:
--
通讯作者:
Jatinder Singh;D. Eyers;J. Bacon
Jatinder Singh;D. Eyers;J. Bacon
中科院分区:
其他
文献类型:
--
作者:
Jatinder Singh;D. Eyers;J. Bacon

文献摘要

相似文献

发布/订阅是广域系统上事件传播的有效范例。然而,在开放信息传递的便利性和保护数据免受未经授权访问的需要之间存在着紧张关系。发布/订阅安全模型往往侧重于保护客户端API,或者通过密钥分发对事件进行加密和管理泄露。然而,某些应用程序环境需要更严格的细粒度控制,以精确地管理在特定情况下披露和传输的数据。在本文中,我们提出了交互控制,一个政策模型,覆盖上下文感知,点对点(跳级)控制到一个发布/订阅网络。该方法是独特的,因为它允许对i)传播网络的构造和ii)网络内的信息流进行粒度控制。互动控制的设计考虑到了法律的义务,使那些负责信息的人能够在需要知道的基础上传输数据。安全策略为通信设置了界限,仅在发布/订阅过程的特定点上必要时才强制执行,以提供控制,同时保持范式的效率优势。我们目前的实施细节和结果表明,任何安全开销必须考虑相对于整体网络负载。
Publish/subscribe is an effective paradigm for event dissemination over wide-area systems. However, there is tension between the convenience of open information delivery, and the need to protect data from unauthorised access. Publish/subscribe security models tend to focus on protecting the client API, or encrypting events and managing disclosure through key distribution. However, some application environments require more stringent, fine-grained controls governing precisely the data disclosed and transmitted given particular circumstances. In this paper, we present Interaction Control, a policy model that overlays context-aware, point-to point (hop-level) controls onto a publish/subscribe network. The approach is unique as it allows granular control over i) the construction of the dissemination network, and ii) the information flows within the network. Interaction Control was designed considering legal obligations, to enable those responsible for information to transmit data on a need-to-know basis. Security policies set the bounds for communication, enforced only where necessary at specific points of the publish/subscribe process, to provide control while retaining the efficiency benefits of the paradigm. We present implementation details and results showing that any security overheads must be considered with respect to the overall network load.