Declarative secure distributed information systems

被引:2
|
作者
Zhou, Wenchao [1 ]
Tao, Tao [2 ]
Loo, Boon Thau [2 ]
Mao, Yun [3 ]
机构
[1] Georgetown Univ, Washington, DC 20057 USA
[2] Univ Penn, Philadelphia, PA 19104 USA
[3] AT&T Labs Res, Florham Pk, NJ 07932 USA
关键词
Declarative networking; Secure query processing; Secure distributed information systems; Distributed trust management;
D O I
10.1016/j.cl.2012.09.002
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems and declarative networking. We make the following contributions. First, we propose the Secure Network Datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog, a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog-programs that incorporate secure communication via authentication and encryption among untrusted nodes. Third, we demonstrate the use of user-defined cryptographic functions for customizing the authentication and encryption mechanisms used for securing protocols. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of secure networked systems implemented using our platform. (c) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1 / 24
页数:24
相关论文
共 50 条
  • [21] On the Secure Conditions for Distributed Storage Systems
    Zhu, Rui
    Guo, Wangmei
    2013 INTERNATIONAL SYMPOSIUM ON NETWORK CODING (NETCOD), 2013,
  • [22] Osmotic management of distributed complex systems: A declarative decentralised approach
    Forti, Stefano
    Lera, Isaac
    Guerrero, Carlos
    Brogi, Antonio
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2022, 34 (10)
  • [23] Distributed Real-Time Managed Systems: A Model-Driven Distributed Secure Information Architecture Platform for Managed Embedded Systems
    Levendovszky, Tihamer
    Dubey, Abhishek
    Otte, William R.
    Balasubramanian, Daniel
    Coglio, Alessandro
    Nyako, Sandor
    Emfinger, William
    Kumar, Pranav
    Gokhale, Aniruddha
    Karsai, Gabor
    IEEE SOFTWARE, 2014, 31 (02) : 62 - 69
  • [24] DECLARATIVE FOUNDATIONS OF SECURE DEDUCTIVE DATABASES
    BONATTI, P
    KRAUS, S
    SUBRAHMANIAN, VS
    LECTURE NOTES IN COMPUTER SCIENCE, 1992, 646 : 391 - 406
  • [25] Toward Distributed Declarative Control of Networked Cyber-Physical Systems
    Stehr, Mark-Oliver
    Kim, Minyoung
    Talcott, Carolyn
    UBIQUITOUS INTELLIGENCE AND COMPUTING, 2010, 6406 : 397 - 413
  • [26] Distributed secure state estimation with a priori sparsity information
    Shinohara, Takumi
    Namerikawa, Toru
    IET CONTROL THEORY AND APPLICATIONS, 2022, 16 (11): : 1086 - 1097
  • [27] DeXteR - An Extensible Framework for Declarative Parameter Passing in Distributed Object Systems
    Gopal, Sriram
    Tansey, Wesley
    Kannan, Gokulnath C.
    Tilevich, Eli
    MIDDLEWARE 2008, PROCEEDINGS, 2008, 5346 : 144 - 163
  • [28] Secure distributed agreement protocols for information assurance applications
    Sabbir, A.
    Ravindran, K.
    Kwiat, K. A.
    2007 2ND INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS SOFTWARE & MIDDLEWARE, VOLS 1 AND 2, 2007, : 890 - +
  • [29] Generalised secure distributed source coding with side information
    Salimi, S.
    Salmasizadeh, M.
    Aref, M. Reza
    IET COMMUNICATIONS, 2010, 4 (18) : 2262 - 2272
  • [30] A DECLARATIVE SPATIAL QUERY PROCESSOR FOR GEOGRAPHIC INFORMATION-SYSTEMS
    MENON, S
    SMITH, TR
    PHOTOGRAMMETRIC ENGINEERING AND REMOTE SENSING, 1989, 55 (11): : 1593 - 1600