Declarative secure distributed information systems

被引:2
|
作者
Zhou, Wenchao [1 ]
Tao, Tao [2 ]
Loo, Boon Thau [2 ]
Mao, Yun [3 ]
机构
[1] Georgetown Univ, Washington, DC 20057 USA
[2] Univ Penn, Philadelphia, PA 19104 USA
[3] AT&T Labs Res, Florham Pk, NJ 07932 USA
关键词
Declarative networking; Secure query processing; Secure distributed information systems; Distributed trust management;
D O I
10.1016/j.cl.2012.09.002
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We present a unified declarative platform for specifying, implementing, and analyzing secure networked information systems. Our work builds upon techniques from logic-based trust management systems and declarative networking. We make the following contributions. First, we propose the Secure Network Datalog (SeNDlog) language that unifies Binder, a logic-based language for access control in distributed systems, and Network Datalog, a distributed recursive query language for declarative networks. SeNDlog enables network routing, information systems, and their security policies to be specified and implemented within a common declarative framework. Second, we extend existing distributed recursive query processing techniques to execute SeNDlog-programs that incorporate secure communication via authentication and encryption among untrusted nodes. Third, we demonstrate the use of user-defined cryptographic functions for customizing the authentication and encryption mechanisms used for securing protocols. Finally, using a local cluster and the PlanetLab testbed, we perform a detailed performance study of a variety of secure networked systems implemented using our platform. (c) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1 / 24
页数:24
相关论文
共 50 条
  • [31] Efficient and secure information sharing in distributed, collaborative environments
    Dasgupta, P
    Karamcheti, V
    Kedem, ZM
    [J]. COMMUNICATION-BASED SYSTEMS, 2000, : 147 - 162
  • [32] A DECLARATIVE SPATIAL QUERY PROCESSOR FOR GEOGRAPHIC INFORMATION-SYSTEMS
    MENON, S
    SMITH, TR
    [J]. PHOTOGRAMMETRIC ENGINEERING AND REMOTE SENSING, 1989, 55 (11): : 1593 - 1600
  • [33] Secure Determinant Codes for Distributed Storage Systems
    Elmahdy, Adel
    Kleckler, Michelle
    Mohajer, Soheil
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 2023, 69 (03) : 1966 - 1987
  • [34] A distributed systems approach to secure Internet mail
    Machanick, P
    [J]. COMPUTERS & SECURITY, 2005, 24 (06) : 492 - 499
  • [35] Scalable and Secure Architecture for Distributed IoT Systems
    Dhieb, Najmeddine
    Ghazzai, Hakim
    Besbes, Hichem
    Massoud, Yehia
    [J]. 2020 IEEE TECHNOLOGY & ENGINEERING MANAGEMENT CONFERENCE (TEMSCON 2020), 2020,
  • [37] Secure Determinant Codes for Distributed Storage Systems
    Cui, Zhongrui
    Cui, Naxin
    Li, Changlong
    Lu, Jianbo
    Zhang, Chenghui
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2023, 70 (05) : 4716 - 4726
  • [38] The Rate Region for Secure Distributed Storage Systems
    Ye, Fangwei
    Shum, Kenneth W.
    Yeung, Raymond W.
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 2017, 63 (11) : 7038 - 7051
  • [39] Secure medical information systems: A model
    Archer, C
    [J]. TOWARD AN ELECTRONIC HEALTH RECORD EUROPE '97 - CONFERENCE ON THE CREATION OF A EUROPEAN ELECTRONIC HEALTH RECORD, CONFERENCE PROCEEDINGS, 1997, : 252 - 256
  • [40] ENGINEERING SECURE INFORMATION-SYSTEMS
    DAVIES, DW
    PRICE, WL
    [J]. LECTURE NOTES IN COMPUTER SCIENCE, 1986, 219 : 191 - 199