Secure event types in content-based, multi-domain publish/subscribe systems

Secure event types in content-based, multi-domain publish/subscribe systems
复制标题

基于内容的多域发布/订阅系统中的安全事件类型

DOI:
--
复制
发表时间:
2005
期刊:
Joint Conference on Lexical and Computational Semantics
影响因子:
--
通讯作者:
J. Bacon
J. Bacon
中科院分区:
--
文献类型:
--
作者:
Lauri I. W. Pesonen;J. Bacon

文献摘要

被引文献

相似文献

到目前为止,发布/订阅的研究主要集中在高效的事件路由、事件过滤和复合事件检测上。已经发表的关于发布/订阅系统中的安全性的少量研究充其量也只是试探性的。本文提出了一种安全类型名的模型,并定义了类型检查的、基于内容的发布/订阅系统。我们的模型在类型名称和类型定义之间提供了可加密验证的绑定。它还生成可自我认证的类型定义,以保证类型定义的真实性和完整性。我们还考虑了大规模发布/订阅系统中的类型管理,并提出了一种通过颁发SPKI授权证书来将管理职责委派给类型管理器的方法。我们认为,安全名称是大多数其他与发布/订阅系统相关的安全工作的先决条件。
Publish/subscribe research has so far been mostly focused on efficient event routing, event filtering, and composite event detection. The little research that has been published regarding security in publish/subscribe systems has been tentative at best. This paper presents a model for secure type names, and definitions for type-checked, content-based publish/subscribe systems. Our model provides a cryptographically verifiable binding between type names and type definitions. It also produces self-certifiable type definitions that guarantee type definition authenticity and integrity. We also consider type management in a large-scale publish/subscribe system and present a way for delegating management duties to type managers by issuing SPKI authorisation certificates. We feel that secure names are a prerequisite for most other security related work with publish/subscribe systems.