NAC: Automating Access Control via Named Data

NAC: Automating Access Control via Named Data
复制标题

NAC:通过命名数据实现自动化访问控制

DOI:
10.1109/milcom.2018.8599774
复制
发表时间:
2018
期刊:
MILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM)
影响因子:
--
通讯作者:
Lixia Zhang
Lixia Zhang
中科院分区:
--
文献类型:
--
作者:
Zhiyi Zhang;Yingdi Yu;Sanjeev Kaushik Ramani;Alexander Afanasyev;Lixia Zhang

文献摘要

被引文献

相似文献

本文提出了一种基于名称的访问控制(NAC)方案,该方案通过在生产时对内容进行加密,并通过自动分发加密和解密密钥来支持命名数据网络(NDN)体系结构中的数据机密性和访问控制。NAC通过利用精心设计的NDN命名约定来定义和实施访问控制策略,并实现加密密钥管理的自动化,从而实现上述设计目标。本文还解释了NDN的层次结构命名空间如何允许NAC支持细粒度的访问控制策略,以及NDN的兴趣-数据交换如何帮助NAC在间歇性连接的情况下发挥作用。此外,我们表明NAC设计可以进一步扩展以支持基于属性的加密(ABE),它支持具有额外灵活性和可伸缩性级别的访问控制。
In this paper we present the design of Name-based Access Control (NAC) scheme, which supports data confidentiality and access control in Named Data Networking (NDN) architecture by encrypting content at the time of production, and by automating the distribution of encryption and decryption keys. NAC achieves the above design goals by leveraging specially crafted NDN naming conventions to define and enforce access control policies, and to automate the cryptographic key management. The paper also explains how NDN's hierarchically structured namespace allows NAC to support fine-grained access control policies, and how NDN's Interest-Data exchange can help NAC to function in case of intermittent connectivity. Moreover, we show that NAC design can be further extended to support Attribute-based Encryption (ABE), which supports access control with additional levels of flexibility and scalability.