Security, Privacy, and Access Control in Information-Centric Networking: A Survey

Security, Privacy, and Access Control in Information-Centric Networking: A Survey
复制标题

DOI:
10.1109/comst.2017.2749508
复制
发表时间:
2018-01-01
影响因子:
35.6
通讯作者:
Panwar, Gaurav
Panwar, Gaurav
中科院分区:
计算机科学1区
文献类型:
--
作者:
Tourani, Reza;Misra, Satyajayant;Panwar, Gaurav

文献摘要

被引文献

相似文献

以信息为中心的网络(ICN)将通信网络(例如,互联网和移动自组织网络)中广泛使用的以主机为中心的网络模式替换为以信息为中心的模式,该模式优先考虑命名内容的递送,而不考虑内容的来源。内容和客户端安全、来源和身份隐私在ICN范例中是固有的设计,而不是当前的以主机为中心的范例,在当前的范例中,它们被当作事后的工具。然而,考虑到它的萌芽,ICN范例有几个公开的安全和隐私问题。在本文中,我们综述了现有的ICN安全和隐私方面的文献,并提出了有待解决的问题。更具体地说,我们探讨了三个广泛的领域:1)安全威胁;2)隐私风险;3)访问控制实施机制。我们介绍了现有工作的基本原理,讨论了提出的方法的缺陷,并探索了未来可能的研究方向。在安全方面,我们回顾了攻击场景,例如拒绝服务、缓存污染和内容中毒。在隐私方面,我们讨论了用户隐私和匿名性、姓名和签名隐私以及内容隐私。ICN的无处不在的缓存功能给访问控制实施带来了一个重大挑战,需要特别关注。我们回顾了现有的访问控制机制,包括基于加密、基于属性、基于会话和基于代理重新加密的访问控制方案。我们总结了调查得出的经验教训和今后工作的范围。
Information-centric networking (ICN) replaces the widely used host-centric networking paradigm in communication networks (e.g., Internet and mobile ad hoc networks) with an information-centric paradigm, which prioritizes the delivery of named content, oblivious of the contents' origin. Content and client security, provenance, and identity privacy are intrinsic by design in the ICN paradigm as opposed to the current host centric paradigm where they have been instrumented as an afterthought. However, given its nascency, the ICN paradigm has several open security and privacy concerns. In this paper, we survey the existing literature in security and privacy in ICN and present open questions. More specifically, we explore three broad areas: 1) security threats; 2) privacy risks; and 3) access control enforcement mechanisms. We present the underlying principle of the existing works, discuss the drawbacks of the proposed approaches, and explore potential future research directions. In security, we review attack scenarios, such as denial of service, cache pollution, and content poisoning. In privacy, we discuss user privacy and anonymity, name and signature privacy, and content privacy. ICN's feature of ubiquitous caching introduces a major challenge for access control enforcement that requires special attention. We review existing access control mechanisms including encryption-based, attribute-based, session-based, and proxy re-encryption-based access control schemes. We conclude the survey with lessons learned and scope for future work.