Securing publish/subscribe for multi-domain systems

被引:0
|
作者
Bacon, J [1 ]
Eyers, D [1 ]
Moody, K [1 ]
Pesonen, L [1 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB3 0FD, England
来源
MIDDLEWARE 2005, PROCEEDINGS | 2005年 / 3790卷
关键词
publish/subscribe; loosely coupled applications; content-based routing; role-based access control; attribute encryption; message confidentiality; trust;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Two convincing paradigms have emerged for achieving scalability in widely distributed systems: role-based, policy-driven control of access to the system by applications and for system management purposes; and publish/subscribe communication between loosely coupled components. Publish/subscribe provides efficient support for mutually anonymous, many-to-many communication between loosely coupled entities. In this paper we focus on securing such a communication service (1) by specifying and enforcing access control policy at the service API, and (2) by enforcing the security and privacy aspects of these policies within the service itself. We envisage independent but related administration domains that share a pub/sub communications infrastructure, typical of public-sector systems. Roles are named within each domain and role-related privileges for using the pub/sub service are specified. Intra- and inter-domain, controlled interaction is supported by negotiated policies. In a large-scale publish/subscribe service, domains are not expected to trust all message brokers fully. Attribute encryption allows a single pubbcation to carry both confidential and public information safely, even via untrusted message brokers across a vulnerable communications substrate. Our approach provides the application designer with fine-grained expressiveness while, at the same time, improving system fault tolerance by allowing a single shared messaging network to route both public and confidential information. Early simulations show that our approach reduces the overall traffic compared with a secure publish/ subscribe scheme that encrypts whole messages.
引用
收藏
页码:1 / 20
页数:20
相关论文
共 50 条
  • [11] Reliable multi-agent systems with persistent publish/subscribe messaging
    Tosic, M
    Zaslavsky, A
    [J]. INNOVATIONS IN APPLIED ARTIFICIAL INTELLIGENCE, 2005, 3533 : 165 - 174
  • [12] Anonymous Publish-Subscribe Systems
    Vo, Binh
    Bellovin, Steven
    [J]. INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT I, 2015, 152 : 195 - 211
  • [13] Parameterized subscriptions in publish/subscribe systems
    Huang, Yongqiang
    Garcia-Molina, Hector
    [J]. DATA & KNOWLEDGE ENGINEERING, 2007, 60 (03) : 435 - 450
  • [14] Modeling uncertainties in publish/subscribe systems
    Liu, HF
    Jacobsen, HA
    [J]. 20TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, PROCEEDINGS, 2004, : 510 - 521
  • [15] Mobility support in publish/subscribe systems
    Antipov, Vladimir
    Antipov, Oleg
    Pylkin, Aleksander
    [J]. 6TH SEMINAR ON INDUSTRIAL CONTROL SYSTEMS: ANALYSIS, MODELING AND COMPUTATION, 2016, 6
  • [16] Towards expressive publish/subscribe systems
    Demers, Alan
    Gehrke, Johannes
    Hong, Mingsheng
    Riedewald, Mirek
    White, Walker
    [J]. ADVANCES IN DATABASE TECHNOLOGY - EDBT 2006, 2006, 3896 : 627 - 644
  • [17] On reliability in publish/subscribe systems: a survey
    Mayer, Tobias R.
    Brunie, Lionel
    Coquil, David
    Kosch, Harald
    [J]. INTERNATIONAL JOURNAL OF PARALLEL EMERGENT AND DISTRIBUTED SYSTEMS, 2012, 27 (05) : 369 - 386
  • [18] On the modelling of publish/subscribe communication systems
    Baldoni, R
    Beraldi, R
    Piergiovanni, STC
    Virgillito, A
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2005, 17 (12): : 1471 - 1495
  • [19] Towards Scalable Publish/Subscribe Systems
    Ji, Shuping
    Ye, Chunyang
    Wei, Jun
    Jacobsen, Hans-Arno
    [J]. 2015 IEEE 35th International Conference on Distributed Computing Systems, 2015, : 784 - 785
  • [20] On the Privacy Protection in Publish/Subscribe Systems
    Chen, Weifeng
    Jiang, Jianchun
    Skocik, Nancy
    [J]. 2010 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND INFORMATION SECURITY (WCNIS), VOL 1, 2010, : 597 - +