TACTIC: Tag-Based Access ConTrol Framework for the Information-Centric Wireless Edge Networks

TACTIC: Tag-Based Access ConTrol Framework for the Information-Centric Wireless Edge Networks
复制标题

DOI:
10.1109/icdcs.2018.00052
复制
发表时间:
2018-07
期刊:
2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS)
影响因子:
--
通讯作者:
R. Tourani;Ray Stubbs;S. Misra
R. Tourani;Ray Stubbs;S. Misra
中科院分区:
其他
文献类型:
--
作者:
R. Tourani;Ray Stubbs;S. Misra

文献摘要

被引文献

相似文献

普适内容缓存是以信息为中心的网络(ICN)的基础之一。尽管具有优势,但普及缓存引入了新的挑战。特别是,内容提供商很有可能失去对其发布内容的控制,客户端可以在不进行身份验证的情况下访问这些内容。构成访问控制中的现有技术的方法具有高计算开销或者需要始终在线的认证服务器,因此在针对大量终端设备的可扩展性方面受到影响。在本文中,我们提出了TACTIC,一个轻量级的访问控制机制的ICN无线边缘,它允许合法的客户端利用缓存的内容,而无需在提供商的每请求认证。TACTIC将身份验证和授权任务委托给ISP网络中的(半信任)路由器,以消除对始终在线身份验证服务器的需求。它可以防止将加密内容发送给未经授权的用户;这是一种浪费带宽的做法,可能导致分布式拒绝服务(DDoS)攻击。实验结果表明,TACTIC的可扩展性和有效性,提供低开销的合法客户端访问,同时防止恶意用户的访问。
Pervasive content caching is one of the information-centric networking (ICN) fundamentals. Although advantageous, pervasive caching introduces new challenges. In particular, the high possibility of content providers losing control over their published contents, which clients can access without authenticating themselves. The approaches that constitute the state-of-the-art in access control either have high computation overhead or require an always-online authentication server, thus suffering in terms of scalability for large number of end devices. In this paper, we propose TACTIC, a lightweight access control mechanism for the ICN wireless edge, which allows legitimate clients to utilize the cached content without per-request authentication at the providers. TACTIC delegates the authentication and authorization tasks to the (semi-trusted) routers in an ISP's network to eliminate the need for an always-online authentication server. It prevents delivery of the encrypted content to unauthorized users; a bandwidth-wasteful practice, which may lead to Distributed Denial of Service (DDoS) attack. Experimental results demonstrate the scalability and effectiveness of TACTIC in providing low-overhead access to legitimate clients while preventing malicious users' access.