Declarative secure distributed information systems

被引:2
|
作者
Zhou, Wenchao [1 ]
Tao, Tao [2 ]
Loo, Boon Thau [2 ]
Mao, Yun [3 ]
机构
[1] Georgetown Univ, Washington, DC 20057 USA
[2] Univ Penn, Philadelphia, PA 19104 USA
[3] AT&T Labs Res, Florham Pk, NJ 07932 USA
关键词
Declarative networking; Secure query processing; Secure distributed information systems; Distributed trust management;
D O I
10.1016/j.cl.2012.09.002
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems and declarative networking. We make the following contributions. First, we propose the Secure Network Datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog, a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog-programs that incorporate secure communication via authentication and encryption among untrusted nodes. Third, we demonstrate the use of user-defined cryptographic functions for customizing the authentication and encryption mechanisms used for securing protocols. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of secure networked systems implemented using our platform. (c) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1 / 24
页数:24
相关论文
共 50 条
  • [1] Unified Declarative Platform for Secure Networked Information Systems
    Zhou, Wenchao
    Mao, Yun
    Loo, Boon Thau
    Abadi, Martin
    [J]. ICDE: 2009 IEEE 25TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, VOLS 1-3, 2009, : 150 - +
  • [2] Secure Information Flow for Distributed Systems
    Alpizar, Rafael
    Smith, Geoffrey
    [J]. FORMAL ASPECTS IN SECURITY AND TRUST, 2010, 5983 : 126 - 140
  • [3] Secure Information Brokering and Sharing in Distributed Systems
    Kumar, G. Siva
    Babu, K. Mahesh
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2015, 15 (11): : 107 - 111
  • [4] Declarative mediation in distributed systems*
    Melnik, S
    [J]. CONCEPTUAL MODELING ER 2000, PROCEEDINGS, 2000, 1920 : 66 - 79
  • [5] Private Information Retrieval for Secure Distributed Storage Systems
    Yang, Heecheol
    Shin, Wonjae
    Lee, Jungwoo
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (12) : 2953 - 2964
  • [6] Declarative programming with Lyee for distributed systems
    Gorlatch, S
    [J]. NEW TRENDS IN SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2004, 111 : 129 - 137
  • [7] Secure Distributed Information Exchange
    Abuzainab, Nof
    Ephremides, Anthony
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 2014, 60 (02) : 1126 - 1135
  • [8] Declarative interaction with geographical information systems
    Copas, C
    Edmonds, E
    [J]. OZCHI 98 - 1998 AUSTRALASIAN COMPUTER HUMAN INTERACTION CONFERENCE, PROCEEDINGS, 1998, : 168 - 175
  • [10] Distributed secure systems: Then and now
    Randell, Brian
    Rushby, John
    [J]. TWENTY-THIRD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2007, : 178 - +