Capability-Based Security Enforcement in Named Data Networking

Capability-Based Security Enforcement in Named Data Networking
复制标题

命名数据网络中基于能力的安全实施

DOI:
10.1109/tnet.2017.2715822
复制
发表时间:
2017
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Ren Kui
Ren Kui
中科院分区:
其他
文献类型:
--
作者:
Li Qi;Lee Patrick P C;Zhang Peng;Su Purui;He Liang;Ren Kui

文献摘要

被引文献

相似文献

命名数据网络(NDN)通过支持网内内容缓存来增强传统的IP网络,从而提高带宽利用率,并为多路径转发提供与位置无关的数据访问。然而,NDN也带来了新的安全挑战。例如,攻击者可以任意向NDN注入数据包以毒化内容缓存,或者不受任何限制地访问内容数据包。我们提出了基于能力的安全实施体系结构(CSEA),这是一种基于能力的安全实施体系结构,能够以分布式的方式在NDN中实现数据的真实性。CSEA利用功能来指定转发的数据包的访问权限。它允许NDN路由器验证转发的数据包的真实性,并遏制来自未经请求的数据包的基于泛洪的DoS攻击。在此基础上,提出了一种适用于CSEA的轻量级一次性签名方案,以保证报文的时效性,并支持高效的验证。我们在开源的CCNx平台上实现了CSEA原型,并通过TestBed和PlanetLab实验对CSEA进行了评估。我们的实验结果表明,CSEA在检索数据分组时仅产生大约4%的额外延迟。
Named data networking (NDN) enhances traditional IP networking by supporting in-network content caching for better bandwidth usage and location-independent data accesses for multi-path forwarding. However, NDN also brings new security challenges. For example, an adversary can arbitrarily inject packets to NDN to poison content cache, or access content packets without any restrictions. We propose capability-based security enforcement architecture (CSEA), a capability-based security enforcement architecture that enables data authenticity in NDN in a distributed manner. CSEA leverages capabilities to specify the access rights of forwarded packets. It allows NDN routers to verify the authenticity of forwarded packets, and throttles flooding-based DoS attacks from unsolicited packets. We further develop a lightweight one-time signature scheme for CSEA to ensure the timeliness of packets and support efficient verification. We prototype CSEA on the open-source CCNx platform, and evaluate CSEA via testbed and Planetlab experiments. Our experimental results show that CSEA only incurs around 4% of additional delays in retrieving data packets.