LIVE: Lightweight Integrity Verification and Content Access Control for Named Data Networking

LIVE: Lightweight Integrity Verification and Content Access Control for Named Data Networking
复制标题

LIVE:命名数据网络的轻量级完整性验证和内容访问控制

DOI:
10.1109/tifs.2014.2365742
复制
发表时间:
2015-02
影响因子:
6.8
通讯作者:
Fu, Xiaoming
Fu, Xiaoming
中科院分区:
计算机科学1区
文献类型:
--
作者:
Zhang, Xinwen;Zheng, Qingji;S;hu, Ravi;Fu, Xiaoming

文献摘要

参考文献

被引文献

相似文献

命名数据网络(NDN)是未来互联网的一种新范式,其中兴趣和数据分组携带内容名称,而不是当前的源地址和目的地址的IP范式。NDN通过在每个数据包中嵌入公钥签名来实现安全性,以验证内容的真实性和完整性。然而,现有的重量级签名生成和验证算法阻止了NDN节点之间的通用完整性验证,这可能导致内容污染和拒绝服务攻击。此外,高速缓存和位置无关的内容访问禁止内容提供商控制内容访问的能力,例如,我们提出了一个轻量级的完整性验证(LIVE)架构,NDN协议的扩展,无缝地解决这两个问题。LIVE通过轻量级签名生成和验证算法在NDN中实现通用内容签名验证。此外,它允许内容提供商通过选择性地向授权节点分发完整性验证令牌来控制NDN节点中的内容访问。我们使用开源的CCNx项目来评估LIVE的有效性。我们的论文表明,LIVE在访问内容时仅产生平均10%的延迟。与传统的公钥签名方案相比,LIVE方案的验证延迟降低了20倍以上。
Named data networking (NDN) is a new paradigm for the future Internet wherein interest and data packets carry content names rather than the current IP paradigm of source and destination addresses. Security is built into NDN by embedding a public key signature in each data packet to enable verification of authenticity and integrity of the content. However, existing heavyweight signature generation and verification algorithms prevent universal integrity verification among NDN nodes, which may result in content pollution and denial of service attacks. Furthermore, caching and location-independent content access disables the capability of a content provider to control content access, e.g., who can cache a content and which end user or device can access it. We propose a lightweight integrity verification (LIVE) architecture, an extension to the NDN protocol, to address these two issues seamlessly. LIVE enables universal content signature verification in NDN with lightweight signature generation and verification algorithms. Furthermore, it allows a content provider to control content access in NDN nodes by selectively distributing integrity verification tokens to authorized nodes. We evaluate the effectiveness of LIVE with open source CCNx project. Our paper shows that LIVE only incurs average 10% delay in accessing contents. Compared with traditional public key signature schemes, the verification delay is reduced by over 20 times in LIVE.
DOI: 10.1145/2377677.2377773
发表时间: 2012-08
期刊: --
影响因子: --
作者:
N. Fotiou;G. Marias;George C. Polyzos
通讯作者: N. Fotiou;G. Marias;George C. Polyzos
DOI: 10.1145/2500098.2500106
发表时间: 2013-07
期刊: Comput. Commun. Rev.
影响因子: --
作者:
G. Bianchi;A. Detti;A. Caponi;N. Blefari-Melazzi
通讯作者: G. Bianchi;A. Detti;A. Caponi;N. Blefari-Melazzi
DOI: 10.1109/infocom.2006.236
发表时间: 2006-04
期刊: Proceedings IEEE INFOCOM 2006. 25TH IEEE International Conference on Computer Communications
影响因子: --
作者:
Hyunseok Chang;S. Jamin;W. Willinger
通讯作者: Hyunseok Chang;S. Jamin;W. Willinger
DOI: 10.1145/1282380.1282402
发表时间: 2007-10
期刊: --
影响因子: --
作者:
T. Koponen;M. Chawla;Byung-Gon Chun;A. Ermolinskiy;Kye Hyun Kim;S. Shenker;I. Stoica
通讯作者: T. Koponen;M. Chawla;Byung-Gon Chun;A. Ermolinskiy;Kye Hyun Kim;S. Shenker;I. Stoica
DOI: --
发表时间: 1998
期刊: --
影响因子: --
作者:
Kan Zhang
通讯作者: Kan Zhang