Access control enforcement delegation for information-centric networking architectures

Access control enforcement delegation for information-centric networking architectures
复制标题

DOI:
10.1145/2377677.2377773
复制
发表时间:
2012-08
期刊:
--
影响因子:
--
通讯作者:
N. Fotiou;G. Marias;George C. Polyzos
N. Fotiou;G. Marias;George C. Polyzos
中科院分区:
其他
文献类型:
--
作者:
N. Fotiou;G. Marias;George C. Polyzos

文献摘要

被引文献

相似文献

信息是信息中心网络 (ICN) 的构建块。访问控制策略仅将信息传播到授权实体。在 ICN 中定义访问控制策略是一项艰巨的任务,因为信息项可能存在于分散在各个网络位置(包括缓存和内容复制服务器)的多个副本中。在本文中,我们提出了一种访问控制执行委托方案,该方案使信息项的提供者能够根据访问控制策略评估请求,而无需访问请求者凭证或策略的实际定义。这种方法具有多种优点:它可以实现各个利益相关者的互操作性,保护用户身份,并可以为隐私保护机制奠定基础。我们计划的实施证明了其可行性。
Information is the building block of Information Centric Networks (ICNs). Access control policies limit information dissemination to authorized entities only. Defining access control policies in an ICN is a non-trivial task as an information item may exist in multiple copies dispersed in various network locations, including caches and content replication servers. In this paper we propose an access control enforcement delegation scheme which enables the purveyor of an information item to evaluate a request against an access control policy, without having access to the requestor credentials nor to the actual definition of the policy. Such an approach has multiple merits: it enables the interoperability of various stakeholders, it protects user identity and it can set the basis for a privacy preserving mechanism. An implementation of our scheme supports its feasibility.