课题基金 / 基金详情

Secure Multicast Services and Applications

Secure Multicast Services and Applications
安全组播服务和应用程序
批准号:
9977292
负责人:
Kenneth Calvert
金额:
$26.3万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
1999
资助国家:
美国
项目状态:
已结题
起止时间:
1999-09-15 至 2005-06-30

项目摘要

项目成果

Kenneth Calvert的其他基金

相似基金

相关文献

中文摘要
翻译
大多数Internet应用程序都基于客户机-服务器范式,并使用作为独立数据包发送的数据的单播传递。保护客户机-服务器计算的单播通信的技术问题是相当容易理解的。然而,许多新兴的Internet应用程序是基于组通信模型的。特别是,它们需要将数据包从一个或多个授权的发送方发送到大量授权的接收方。此外,许多这些应用程序的数据应该被视为流,而不是独立的数据包。从概念上讲,由于每个点对多点通信都可以表示为一组点对点通信,并且每个流都可以视为单个数据包的序列,因此当前用于保护单播数据包的技术基础可以以一种直接的方式扩展到保护使用流和组播的应用程序。然而,这样的扩展将是非常低效的。它们不适用于高速传输和对延迟敏感的流,也不适用于大型组。本提案的目标是研究保护多播和流应用程序的体系结构和协议,重点是效率、延迟和可扩展性。研究人员在可扩展组密钥管理和高效数字签名方面取得了一些初步成果。这些是设计和实现安全多播服务的基本要素。然而,为了在Internet上设计一种可扩展的安全多播服务,即使只是尽最大努力交付,仍然存在几个研究问题,即替代体系结构的性能比较,rekey消息的高效可靠交付(及其对广域网的影响),以及可信组件和活动代理的部署。研究人员接下来提出研究更困难的可靠安全组播问题。对于互联网来说,这个问题在很大程度上还没有被探索过。最初,他们计划从两个方向来解决这个问题,即(i)如何使可靠组播安全,(ii)如何使安全组播可靠。在解决这个问题时,我们首先关心的是正确性,其次是性能问题,比如延迟和可伸缩性。有许多应用程序可以从保护流和多播的技术和服务中受益,例如,电话会议、按次付费、信息服务、虚拟专用网络、协作工作、软件分发等。研究人员建议对其中的一些应用进行实验。特别是,他们提出研究一个不太明显的应用,即主动网络,这提出了一些有趣的研究问题。保护活动网络是一个重要的问题,涉及许多不同的关注点,其中一些正在由其他研究人员解决。在提出的项目中,研究人员主要关注动态网络中移动代码分发的真实性和保密性要求的特征,并使用有效的方法确保满足这些要求。
英文摘要
Most Internet applications are based upon the client-server paradigm and make use of unicast delivery of data sent as independent packets. The technical issues of securing unicast communications for client-server computing is fairly well understood. However, many emerging Internet applications are based upon a group communications model. In particular, they require packet delivery from one or more authorized senders to a large number of authorized receivers. Furthermore, the data of many of these applications should be viewed as flows rather than as independent packets. Conceptually, since every point-to-multipoint communication can be represented as a set of point-to-point communications, and every flow can be treated as a sequence of individual packets, the current technology base for securing unicast packets can be extended in a straightforward manner to securing applications that employ flows and multicasts. Such extensions, however, would be highly inefficient. They will not be applicable to high-speed transmission and delay-sensitive flows, nor scalable to large groups.The objectives of this proposal are to investigate architectures and protocols for securing multicast and flow applications with emphasis on efficiency, latency, and scalability. The researchers have obtained some preliminary results on scalable group key management and efficient digital signatures. These are essential ingredients for designing and implementing secure multicast services. However, to design a scalable service for secure multicast on the Internet, even with just best-effort delivery, several research issues remain, namely, performance comparison of alternative architectures, efficient and reliable delivery of rekey messages (and their impact on a wide area network), and deployment of trusted components and active agents.The researchers next propose to investigate the more difficult problem of reliable secure multicast. For the Internet, this problem has been largely unexplored. Initially, they plan to approach this problem from two directions, namely, (i) how to make reliable multicast secure, and (ii) how to make secure multicast reliable. In addressing this problem, our concerns are, first, correctness, and second, performance issues such as latency and scalability.There are many applications that can benefit from techniques and services for securing flows and multicasts, e.g., teleconference, pay per view, information services, virtual private networks, collaborative work, software distribution, etc. The researchers propose to experiment with some of these applications. In particular, they propose to investigate a less obvious application, namely, active networks, which raises some interesting research issues. Securing active networks is an important problem with many different concerns, some of which are being addressed by other researchers. In the proposed project, the researchers are primarily concerned with characterizing the authenticity and confidentiality requirements of mobile code distribution in active networks and ensuring their satisfaction using efficient methods.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CRI-II-NEW: Collaborative Research: Measurement Infrastructure for Home Networks
NetSE: Medium: Collaborative Research: Towards Human-Network Interaction (HNI) for the Home
NeTS-NBD: Collaborative Research: Human-Centered Networking for the Home
Nets-FIND: Collaborative Research: Postmodern Internetwork Architecture
海外基金