A capability-based access control architecture for multi-domain publish/subscribe systems

被引:4
|
作者
Pesonen, LIW [1 ]
Eyers, DM [1 ]
Bacon, J [1 ]
机构
[1] Univ Cambridge, Comp Lab, JJ Thomson Ave, Cambridge CB3 0FD, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
10.1109/SAINT.2006.1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Publish/subscribe has emerged as an attractive communication paradigm for building Internet-wide distributed systems by decoupling message senders from receivers. So far most of the research on publish/subscribe has focused on efficient event routing, event filtering, and composite event detection. Very little research has been published regarding securing publish/subscribe systems. In this paper we present a capability-based access control architecture that enables multiple domains to co-operate in order to build a shared, wide-scale publish/subscribe system. Our architecture employs SPKI authorisation certificates for delegating access control responsibilities to access control services within independent domains in order to balance security and scalability. The architecture supports controlling access both for new event brokers joining the broker network as well as for clients accessing the publish/subscribe API.
引用
收藏
页码:222 / +
页数:2
相关论文
共 50 条
  • [1] Securing publish/subscribe for multi-domain systems
    Bacon, J
    Eyers, D
    Moody, K
    Pesonen, L
    [J]. MIDDLEWARE 2005, PROCEEDINGS, 2005, 3790 : 1 - 20
  • [2] Capability-based access control model for distributed systems
    Zheng, Qingji
    Chen, Kefei
    [J]. ADVANCING SCIENCE THROUGH COMPUTATION, 2008, : 104 - 109
  • [3] Assignment of Multicast Groups to Publish/Subscribe Topics in Multi-Domain Networks
    Holopainen, Visa
    [J]. 2011 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2011,
  • [4] Blockchain-based access control architecture for multi-domain environments
    Du, Zhiqiang
    Li, Yunliang
    Fu, Yanfang
    Zheng, Xianghan
    [J]. PERVASIVE AND MOBILE COMPUTING, 2024, 98
  • [5] ON ACCESS CHECKING IN CAPABILITY-BASED SYSTEMS
    KAIN, RY
    LANDWEHR, CE
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1987, 13 (02) : 202 - 207
  • [6] A Traceable Capability-based Access Control for IoT
    Li, Chao
    Li, Fan
    Huang, Cheng
    Yin, Lihua
    Luo, Tianjie
    Wang, Bin
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (03): : 4967 - 4982
  • [7] MULTIPLE ACCESS CONTROL POLICIES IN CAPABILITY-BASED PROTECTION SYSTEMS.
    Antonelli, Silvano
    Iazeolla, Giuseppe
    [J]. Journal of Information Processing, 1983, 6 (01) : 16 - 22
  • [8] VirtusCap: Capability-based Access Control for Unikernels
    Sfyrakis, Ioannis
    Gross, Thomas
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2017), 2017, : 226 - 237
  • [9] A jini-based publish and subscribe capability
    Combs, VT
    Linderman, M
    [J]. JAVA/JINI TECHNOLOGIES AND HIGH-PERFORMANCE PERVASIVE COMPUTING, 2002, 4863 : 59 - 69
  • [10] Safety in Discretionary Access Control for Logic-based Publish-Subscribe Systems
    Minami, Kazuhiro
    Borisov, Nikita
    Gunter, Carl A.
    [J]. SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 3 - 12