A capability-based access control architecture for multi-domain publish/subscribe systems

被引:4
|
作者
Pesonen, LIW [1 ]
Eyers, DM [1 ]
Bacon, J [1 ]
机构
[1] Univ Cambridge, Comp Lab, JJ Thomson Ave, Cambridge CB3 0FD, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
10.1109/SAINT.2006.1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Publish/subscribe has emerged as an attractive communication paradigm for building Internet-wide distributed systems by decoupling message senders from receivers. So far most of the research on publish/subscribe has focused on efficient event routing, event filtering, and composite event detection. Very little research has been published regarding securing publish/subscribe systems. In this paper we present a capability-based access control architecture that enables multiple domains to co-operate in order to build a shared, wide-scale publish/subscribe system. Our architecture employs SPKI authorisation certificates for delegating access control responsibilities to access control services within independent domains in order to balance security and scalability. The architecture supports controlling access both for new event brokers joining the broker network as well as for clients accessing the publish/subscribe API.
引用
收藏
页码:222 / +
页数:2
相关论文
共 50 条
  • [11] Capability-based access control for multi-tenant systems using OAuth 2.0 and Verifiable Credentials
    Fotiou, Nikos
    Siris, Vasilios A.
    Polyzos, George C.
    [J]. 30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [12] A New Hybrid Access Control Model for Multi-domain Systems
    Hasiba, Ben Attia
    Kahloul, Laid
    Benharzallah, Saber
    [J]. 2017 4TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT), 2017, : 766 - 771
  • [13] Design and implementation of a confidentiality and access control solution for publish/subscribe systems
    Ion, Mihaela
    Russello, Giovanni
    Crispo, Bruno
    [J]. COMPUTER NETWORKS, 2012, 56 (07) : 2014 - 2037
  • [14] Contego: Capability-Based Access Control for Web Browsers
    Luo, Tongbo
    Du, Wenliang
    [J]. TRUST AND TRUSTWORTHY COMPUTING, TRUST 2011, 2011, 6740 : 231 - 238
  • [15] Capability-based IoT access control using blockchain
    Liu, Yue
    Lu, Qinghua
    Chen, Shiping
    Qu, Qiang
    O'Connor, Hugo
    Choo, Kim-Kwang Raymond
    Zhang, He
    [J]. DIGITAL COMMUNICATIONS AND NETWORKS, 2021, 7 (04) : 463 - 469
  • [16] Capability-based IoT access control using blockchain
    Yue Liu
    Qinghua Lu
    Shiping Chen
    Qiang Qu
    Hugo OConnor
    KimKwang Raymond Choo
    He Zhang
    [J]. Digital Communications and Networks, 2021, 7 (04) : 463 - 469
  • [17] A Capability-Based Access Control Framework with Delegation Support
    Shen, Haibo
    [J]. WIRELESS COMMUNICATIONS, NETWORKING AND APPLICATIONS, WCNA 2014, 2016, 348 : 655 - 667
  • [18] A Multi-Domain Access Control Infrastructure Based on Diameter and EAP
    Ben Ayed, Souheil
    Teraoka, Fumio
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2012, E95D (02) : 503 - 513
  • [19] Capability-based egress network access control for transferring access rights
    Suzuki, S
    Shinjo, Y
    Hirotsu, T
    Itano, K
    Kato, K
    [J]. Third International Conference on Information Technology and Applications, Vol 2, Proceedings, 2005, : 488 - 495
  • [20] Towards an access control mechanism for wide-area publish/subscribe systems
    Miklós, Z
    [J]. 22ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOP, PROCEEDINGS, 2002, : 516 - 521