Capability-Based Security Enforcement in Named Data Networking
Capability-Based Security Enforcement in Named Data Networking
复制标题
命名数据网络中基于能力的安全实施
DOI:
10.1109/tnet.2017.2715822
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Ren Kui
中科院分区:
文献类型:
--
作者:
Li Qi;Lee Patrick P C;Zhang Peng;Su Purui;He Liang;Ren Kui
Named data networking (NDN) enhances traditional IP networking by supporting in-network content caching for better bandwidth usage and location-independent data accesses for multi-path forwarding. However, NDN also brings new security challenges. For example, an adversary can arbitrarily inject packets to NDN to poison content cache, or access content packets without any restrictions. We propose capability-based security enforcement architecture (CSEA), a capability-based security enforcement architecture that enables data authenticity in NDN in a distributed manner. CSEA leverages capabilities to specify the access rights of forwarded packets. It allows NDN routers to verify the authenticity of forwarded packets, and throttles flooding-based DoS attacks from unsolicited packets. We further develop a lightweight one-time signature scheme for CSEA to ensure the timeliness of packets and support efficient verification. We prototype CSEA on the open-source CCNx platform, and evaluate CSEA via testbed and Planetlab experiments. Our experimental results show that CSEA only incurs around 4% of additional delays in retrieving data packets.