Secure Multicast Services and Applications
Secure Multicast Services and Applications
批准号:
9977267
负责人:
Simon Lam
金额:
$53.65万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
1999
资助国家:
美国
项目状态:
已结题
起止时间:
1999-09-15 至 2003-08-31
中文摘要
这是由德克萨斯大学奥斯汀分校(PI:Simon S.Lam)和肯塔基大学(PI:Kenneth Calvert)提交的一项合作研究提案。大多数互联网应用程序基于客户端-服务器模式,并使用单传输作为独立分组发送的数据。保护客户端-服务器计算的单播通信的技术问题是相当清楚的。然而,许多新兴的互联网应用都是基于群组通信模型的。特别是,它们需要从一个或多个授权发送者向大量授权接收者递送包裹。此外,这些应用中的许多数据应该被视为流,而不是独立的分组。从概念上讲,由于每个点对多点通信可以被表示为一组点对点通信,并且每个流可以被视为一个单独分组的序列,所以当前用于保护单播分组的技术基础可以以一种直接的方式扩展到使用流和多播的安全应用。然而,这样的延期将是非常低效的。它们不适用于高速传输和时延敏感的网络,也不能扩展到大群组。本方案的目标是研究用于保护多播和流应用的体系结构和协议,重点是效率、延迟和可扩展性。研究人员在可扩展的组密钥管理和高效的数字签名方面已经取得了一些初步的结果。这些都是设计和实现安全组播服务的基本要素。然而,为了设计一种可扩展的Internet上的安全组播服务,即使只使用尽力而为的传输,仍然存在几个研究问题,即替代体系结构的性能比较、高效可靠地传递更新密钥消息(及其对广域网的影响)以及可信组件和主动代理的部署。对于互联网来说,这个问题在很大程度上还没有被探索过。最初,研究人员计划从两个方向来解决这个问题,即(I)如何使可靠组播安全,(Ii)如何使安全组播可靠。在解决这个问题时,他们首先关注的是正确性,其次是延迟和可扩展性等性能问题。有许多应用程序可以受益于保护流和多播的技术和服务,例如电话会议、按次付费、信息服务、虚拟专用网络、协作工作、软件分发等。研究人员建议对其中一些应用程序进行试验。特别是,他们建议调查一个不太明显的应用,即主动网络,这引发了一些有趣的研究问题。主动网络的安全是一个重要的问题,有许多不同的问题,其中一些正在被其他研究人员解决。在提出的项目中,研究人员主要关注主动网络中移动代码分发的真实性和保密性要求,并使用有效的方法确保它们的满足。
英文摘要
This is a collaborative research proposal being submitted by the University of Texas at Austin(PI: Simon S. Lam) and the University of Kentucky (PI: Kenneth Calvert).Most Internet applications are based upon the client-server paradigm and make use of unicastdelivery of data sent as independent packets. The technical issues of securing unicast communi-cations for client-server computing are fairly well understood. However, many emerging Internetapplications are based upon a group communications model. In particular, they require packetdelivery from one or more authorized senders to a large number of authorized receivers. Further-more, the data of many of these applications should be viewed as flows rather than as independentpackets. Conceptually, since every point-to-multipoint communication can be represented as a setof point-to-point communications, and every flow can be treated as a sequence of individual pack-ets, the current technology base for securing unicast packets can be extended in a straightforwardmanner to securing applications that employ flows and multicasts. Such extensions, however, wouldbe highly inefficient. They will not be applicable to high-speed transmission and delay-sensitiveows, nor scalable to large groups.The objectives of this proposal are to investigate architectures and protocols for securing mul-ticast and flow applications with emphasis on efficiency, latency, and scalability. The researchers have obtained some preliminary results on scalable group key management and efficient digital signatures. Theseare essential ingredients for designing and implementing secure multicast services. However, to de-sign a scalable service for secure multicast on the Internet, even with just best-effort delivery, severalresearch issues remain, namely, performance comparison of alternative architectures, efficient andreliable delivery of rekey messages (and their impact on a wide area network), and deployment oftrusted components and active agents.The researchers next propose to investigate the more difficult problem of reliable secure multicast. For theInternet, this problem has been largely unexplored. Initially, the researchers plan to approach this problemfrom two directions, namely, (i) how to make reliable multicast secure, and (ii) how to make securemulticast reliable. In addressing this problem, their concerns are, first, correctness, and second,performance issues such as latency and scalability.There are many applications that can benefit from techniques and services for securing flowsand multicasts, e.g., teleconference, pay per view, informaton services, virtual private networks,collaborative work, software distribution, etc. The researchers propose to experiment with some of these applications. In particular, they propose to investigate a less obvious application, namely, active networks,which raises some interesting research issues. Securing active networks is an important problemwith many different concerns, some of which are being addressed by other researchers. In the pro-posed project, the researchers are primarily concerned with characterizing the authenticity and confidentiality requirements of mobile code distribution in active networks and ensuring their satisfaction using efficient methods.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NeTS: Small: An Efficient Reachability Analysis Method for Large Dynamic Networks and Its Applications
-
批准号:1214239
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2012
-
负责人:Simon Lam
-
依托单位:
NECO: Protocol Design for Distributed Delaunay Triangulation and Its Applications
-
批准号:0830939
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2008
-
负责人:Simon Lam
-
依托单位:
NeTS-NR: A Novel Technique to Detect Shared Congestion and Applications
-
批准号:0434515
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2004
-
负责人:Simon Lam
-
依托单位:
Networking Research: A Foundation for Designing Overlay Network Protocols
-
批准号:0319168
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2003
-
负责人:Simon Lam
-
依托单位:
Packet Network Architecture and Prorocols for Video Services
-
批准号:9506048
-
项目类别:Standard Grant
-
资助金额:$44.99万
-
财政年份:1995
-
负责人:Simon Lam
-
依托单位:
A Theoretical Foundation for Communication Network Protocols
-
批准号:9004464
-
项目类别:Continuing Grant
-
资助金额:$33.85万
-
财政年份:1990
-
负责人:Simon Lam
-
依托单位:
Fundamental Problems in Communication Network Protocols
-
批准号:8613338
-
项目类别:Continuing Grant
-
资助金额:$33.32万
-
财政年份:1987
-
负责人:Simon Lam
-
依托单位:
Protocols For Communication and Network Resource Allocation
-
批准号:8304734
-
项目类别:Continuing Grant
-
资助金额:$22.17万
-
财政年份:1983
-
负责人:Simon Lam
-
依托单位:
Resource Allocation For Computer Communication Networks
-
批准号:7801803
-
项目类别:Standard Grant
-
资助金额:$21.54万
-
财政年份:1978
-
负责人:Simon Lam
-
依托单位:
海外基金