A capability-based access control architecture for multi-domain publish/subscribe systems

被引:4
|
作者
Pesonen, LIW [1 ]
Eyers, DM [1 ]
Bacon, J [1 ]
机构
[1] Univ Cambridge, Comp Lab, JJ Thomson Ave, Cambridge CB3 0FD, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
10.1109/SAINT.2006.1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Publish/subscribe has emerged as an attractive communication paradigm for building Internet-wide distributed systems by decoupling message senders from receivers. So far most of the research on publish/subscribe has focused on efficient event routing, event filtering, and composite event detection. Very little research has been published regarding securing publish/subscribe systems. In this paper we present a capability-based access control architecture that enables multiple domains to co-operate in order to build a shared, wide-scale publish/subscribe system. Our architecture employs SPKI authorisation certificates for delegating access control responsibilities to access control services within independent domains in order to balance security and scalability. The architecture supports controlling access both for new event brokers joining the broker network as well as for clients accessing the publish/subscribe API.
引用
收藏
页码:222 / +
页数:2
相关论文
共 50 条
  • [21] Evaluation of an IoT Application-Scoped Access Control Model over a Publish/Subscribe Architecture Based on FIWARE
    Pozo, Alejandro
    Alonso, Alvaro
    Salvachua, Joaquin
    SENSORS, 2020, 20 (15) : 1 - 19
  • [22] THE ARCHITECTURE OF A CAPABILITY-BASED MICROPROCESSOR SYSTEM
    CORSINI, P
    LOPRIORE, L
    IEEE MICRO, 1987, 7 (03) : 35 - 51
  • [23] CAPLets: Resource Aware, Capability-Based Access Control for IoT
    Bakir, Fatih
    Krintz, Chandra
    Wolski, Rich
    2021 ACM/IEEE 6TH SYMPOSIUM ON EDGE COMPUTING (SEC 2021), 2021, : 106 - 120
  • [24] Monitoring distributed systems - A publish/subscribe methodology and architecture
    Witting, K
    Challenger, J
    O'Connell, B
    INTEGRATED NETWORK MANAGEMENT VIII: MANAGING IT ALL, 2003, 118 : 89 - 92
  • [25] Fused access control mechanism based on usage control in multi-domain environment
    Yang, Zan
    Wang, Jian-Xin
    Yang, Lin
    Liu, Xiao-Ming
    Wei, Zhen-Zhen
    Chen, Jie-Kun
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2014, 44 (01): : 158 - 163
  • [26] An Access Control Scheme for Multi-agent Systems over Multi-Domain Environments
    Martinez-Garcia, C.
    Navarro-Arribas, G.
    Borrell, J.
    Martin-Campillo, A.
    7TH INTERNATIONAL CONFERENCE ON PRACTICAL APPLICATIONS OF AGENTS AND MULTI-AGENT SYSTEMS (PAAMS 2009), 2009, 55 : 401 - +
  • [27] JCCAP: Capability-based access control for Java']Java Card
    Hagimont, D
    Vandewalle, JJ
    SMART CARD RESEARCH AND ADVANCED APPLICATIONS, 2000, 52 : 365 - 388
  • [28] Secure Data-Centric Access Control for Smart Grid Services Based on Publish/Subscribe Systems
    Duan, Li
    Liu, Dongxi
    Zhang, Yang
    Chen, Shiping
    Liu, Ren Ping
    Cheng, Bo
    Chen, Junliang
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2016, 16 (04)
  • [29] Trust Based Access Control Policy in Multi-domain of Cloud Computing
    Lin, Guoyuan
    Bie, Yuyu
    Lei, Min
    JOURNAL OF COMPUTERS, 2013, 8 (05) : 1357 - 1365
  • [30] Trust-based Access Control Model in Multi-domain Environment
    Zhang Qikun
    Wang Ruifang
    Qu Jiaqing
    Gan Yong
    Zheng Jun
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (05): : 149 - 160