SEANAC: Schema Enforced Automation of Name-based Access Control

被引:0
|
作者
Podder, Proyash [1 ]
Afanasyev, Alexander [1 ]
机构
[1] Florida Int Univ, Miami, FL 33199 USA
关键词
Named Data Networking; Access Control Policy; Name-based Access Control;
D O I
10.1109/ICNC57223.2023.10073994
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Name-based Access Control (NAC) facilitates access control by utilizing NDN's data-centric security and naming convention. NAC design includes three agents: (a) Encryptors, (b) Decryptors, and (c) Access Manager. Encryptors encrypts the content (data) symmetrically using a Content Key (CK). This CK is later encrypted asymmetrically using a Key Encryption Key (KEK). A corresponding KDK is used to decrypt the CK first by the decryptor, and eventually decrypt the content using that CK. Note that, KDK is private and access manager will provide a KDK only to a certain entity if it has access to that data. Access manager is responsible for generating and managing both KEK and KDK. However, in NAC design, there is not any specific mention of how an access manager gets the knowledge of following two things: (a) which KEK will be used to encrypt which CK and (b) which users will have access to which KDK. On the implementation side, these two things are configured manually. However, is a system with a significant number of entities, manually configuring this would not be a feasible approach. Therefore, to automate this process, we have proposed SEANAC, which is a schema-enforced approach to automate the overall NAC process by addressing the two issues mentioned above. In this paper, we have described our design choices and implementation details of SEANAC. Besides, we have evaluated our approach by experimenting with an NDN-based application, Hydra; what are the access control requirements of Hydra, and how SEANAC can be used to fulfill those requirements and build an automated access control system.
引用
收藏
页码:586 / 590
页数:5
相关论文
共 50 条
  • [41] A Study for a Name-based Coordination of Autonomic IoT Functions
    Asaamoning, Godwin
    Mendes, Paulo
    2018 14TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB 2018), 2018, : 296 - 302
  • [42] Fungal Genomics Challenges the Dogma of Name-Based Biosecurity
    McTaggart, Alistair R.
    van der Nest, Magriet A.
    Steenkamp, Emma T.
    Roux, Jolanda
    Slippers, Bernard
    Shuey, Louise S.
    Wingfield, Michael J.
    Drenth, Andre
    PLOS PATHOGENS, 2016, 12 (05)
  • [43] Malaysian Name-based Ethnicity Classification using LSTM
    Hur, Youngbum
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (12): : 3855 - 3867
  • [44] A Name-Based Secure Communications Architecture for Vehicular Networks
    Papadopoulos, Christos
    Afanasyev, Alexander
    Shannigrahi, Susmit
    2021 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2021, : 178 - 181
  • [45] Name-Based Behavioral Biases: Are Expert Investors Immune?
    Itzkowitz, Jennifer
    Itzkowitz, Jesse
    JOURNAL OF BEHAVIORAL FINANCE, 2017, 18 (02) : 180 - 188
  • [46] On-Demand Routing for Scalable Name-Based Forwarding
    Ascigil, Onur
    Rene, Sergi
    Psaras, Ioannis
    Pavlou, George
    PROCEEDINGS OF THE 5TH ACM CONFERENCE ON INFORMATION-CENTRIC NETWORKING (ICN'18), 2018, : 67 - 76
  • [47] Online Name-Based Navigation for Software Meta-languages
    Mosses, Peter D.
    PROCEEDINGS OF THE 16TH ACM SIGPLAN INTERNATIONAL CONFERENCE ON SOFTWARE LANGUAGE ENGINEERING, SLE 2023, 2023, : 220 - 225
  • [48] Estimating the sensitivity and specificity of matching name-based with non-name-based case registries
    Etkind, P
    Tang, Y
    Whelan, M
    Ratelle, S
    Murphy, J
    Sharnprapai, S
    Demaria, A
    EPIDEMIOLOGY AND INFECTION, 2003, 131 (01): : 669 - 674
  • [49] Packet forwarding: Name-based vs. prefix-based
    Shue, Craig A.
    Gupta, Minaxi
    2007 IEEE GLOBAL INTERNET SYMPOSIUM, 2007, : 73 - 78
  • [50] Name-based Routing with On-Path Name Lookup in Information-Centric Network
    Guan, Yu
    Huang, Lemei
    Zhang, Xinggong
    Guo, Zongming
    2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,