Securing publish/subscribe for multi-domain systems

被引:0
|
作者
Bacon, J [1 ]
Eyers, D [1 ]
Moody, K [1 ]
Pesonen, L [1 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB3 0FD, England
来源
MIDDLEWARE 2005, PROCEEDINGS | 2005年 / 3790卷
关键词
publish/subscribe; loosely coupled applications; content-based routing; role-based access control; attribute encryption; message confidentiality; trust;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Two convincing paradigms have emerged for achieving scalability in widely distributed systems: role-based, policy-driven control of access to the system by applications and for system management purposes; and publish/subscribe communication between loosely coupled components. Publish/subscribe provides efficient support for mutually anonymous, many-to-many communication between loosely coupled entities. In this paper we focus on securing such a communication service (1) by specifying and enforcing access control policy at the service API, and (2) by enforcing the security and privacy aspects of these policies within the service itself. We envisage independent but related administration domains that share a pub/sub communications infrastructure, typical of public-sector systems. Roles are named within each domain and role-related privileges for using the pub/sub service are specified. Intra- and inter-domain, controlled interaction is supported by negotiated policies. In a large-scale publish/subscribe service, domains are not expected to trust all message brokers fully. Attribute encryption allows a single pubbcation to carry both confidential and public information safely, even via untrusted message brokers across a vulnerable communications substrate. Our approach provides the application designer with fine-grained expressiveness while, at the same time, improving system fault tolerance by allowing a single shared messaging network to route both public and confidential information. Early simulations show that our approach reduces the overall traffic compared with a secure publish/ subscribe scheme that encrypts whole messages.
引用
收藏
页码:1 / 20
页数:20
相关论文
共 50 条
  • [1] A capability-based access control architecture for multi-domain publish/subscribe systems
    Pesonen, LIW
    Eyers, DM
    Bacon, J
    [J]. INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET , PROCEEDINGS, 2006, : 222 - +
  • [2] MagikCube: Securing Cross-Domain Publish/Subscribe Systems with Enclave
    Wang, Shuran
    Pan, Dahan
    Feng, Runhan
    Zhang, Yuanyuan
    [J]. 2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 147 - 154
  • [3] Assignment of Multicast Groups to Publish/Subscribe Topics in Multi-Domain Networks
    Holopainen, Visa
    [J]. 2011 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2011,
  • [4] On Securing Publish-Subscribe Systems with Security Groups
    Dini, Gianluca
    Lo Duca, Angelica
    [J]. ISCC: 2009 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, VOLS 1 AND 2, 2009, : 531 - 536
  • [5] Securing Autonomous Systems in Multi-domain Tactical Environment
    Le, Dy D.
    Pham, Vung
    Dang, Tommy
    [J]. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS II, 2020, 11413
  • [6] Dynamic Publish/Subscribe Systems
    Antipov, Vladimir A.
    Antipov, Oleg V.
    Pilkin, Aleksandor N.
    [J]. 2014 INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGIES IN PHYSICAL AND ENGINEERING APPLICATIONS (ICCTPEA), 2014, : 11 - 11
  • [7] Publish/Subscribe Systems in Tourism
    Salvador, Zigor
    Alzua, Aurkene
    Lafuente, Alberto
    Larrea, Mikel
    [J]. INFORMATION AND COMMUNICATION TECHNOLOGIES IN TOURISM 2011, 2011, : 319 - +
  • [8] Multi-client Transactions in Distributed Publish/Subscribe Systems
    Jergler, Martin
    Zhang, Kaiwen
    Jacobsen, Hans-Arno
    [J]. 2018 IEEE 38TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2018, : 120 - 131
  • [9] EventGuard: A System Architecture for Securing Publish-Subscribe Networks
    Srivatsa, Mudhakar
    Liu, Ling
    Iyengar, Arun
    [J]. ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2011, 29 (04):
  • [10] Securing Broker-Less Publish/Subscribe Systems Using Identity-Based Encryption
    Tariq, Muhammad Adnan
    Koldehofe, Boris
    Rothermel, Kurt
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (02) : 518 - 528