Mandatory Content Access Control for Privacy Protection in Information Centric Networks

被引:31
|
作者
Li, Qi [1 ,2 ]
Sandhu, Ravi [2 ]
Zhang, Xinwen [3 ]
Xu, Mingwei [4 ,5 ]
机构
[1] Tsinghua Univ, Grad Sch Shenzhen, Shenzhen 518055, Peoples R China
[2] Univ Texas San Antonio, Inst Cyber Secur, San Antonio, TX 78249 USA
[3] Samsung Res Ctr, Santa Clara, CA USA
[4] Tsinghua Univ, Dept Comp Sci, Beijing 100084, Peoples R China
[5] Tsinghua Natl Lab Informat Sci & Technol, Beijing 100084, Peoples R China
基金
美国国家科学基金会; 中国国家自然科学基金;
关键词
Access control; privacy protection; information centric networks; SYSTEM;
D O I
10.1109/TDSC.2015.2494049
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Several Information Centric Network (ICN) architectures have been proposed as candidates for the future Internet, aiming to solve several salient problems in the current IP-based Internet architecture such as mobility, content dissemination and multi-path forwarding. In general, security and privacy are considered as essential requirements in ICN. However, existing ICN designs lack built-in privacy protection for content providers (CPs), e.g., any router in an Internet Service Provider in ICN can cache any content, which may result in information leakage. In this paper, we propose Mandatory Content Access Control (MCAC), a distributed information flow control mechanism to enable a content provider to control which network nodes can cache its contents. In MCAC, a CP defines different security labels for different contents, and content routers check these labels to decide if a content object should be cached. To ensure correct enforcement of MCAC, we also propose a design of a trusted architecture by extending existing mainstream router architectures. We evaluate the performance of MCAC in the NS-3 simulator. The simulation results show that enforcing MCAC in routers does not introduce significant overhead in content forwarding.
引用
收藏
页码:494 / 506
页数:13
相关论文
共 50 条
  • [1] Timing Attacks on Access Privacy in Information Centric Networks and Countermeasures
    Mohaisen, Aziz
    Mekky, Hesham
    Zhang, Xinwen
    Xie, Haiyong
    Kim, Yongdae
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2015, 12 (06) : 675 - 687
  • [2] Optimized Access Control Enforcement Over Encrypted Content in Information-centric Networks
    Mannes, Elisa
    Maziero, Carlos
    Lassance, Luiz
    Borges, Fabio
    [J]. 2015 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2015, : 924 - 929
  • [3] Security, Privacy, and Access Control in Information-Centric Networking: A Survey
    Tourani, Reza
    Misra, Satyajayant
    Mick, Travis
    Panwar, Gaurav
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 566 - 600
  • [4] PROTECTOR: Privacy-Preserving Information Lookup in Content-Centric Networks
    Asghar, Muhammad Rizwan
    Bernardini, Cesar
    Crispo, Bruno
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [5] Privacy Protection and Access Control of Image Information Processing Devices
    Yi, Kijung
    Han, Minho
    Park, Jong Hyuk
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2011, 12 (05): : 711 - 716
  • [6] A Formally Verified Access Control Mechanism for Information Centric Networks
    Aiash, Mahdi
    Loo, Jonathan
    [J]. 2015 12TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (ICETE), VOL 4, 2015, : 377 - 383
  • [7] Privacy-centric Access Control for Distributed Heterogeneous Medical Information Systems
    Khan, Atif
    McKillop, Ian
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON HEALTHCARE INFORMATICS (ICHI 2013), 2013, : 297 - 306
  • [8] Formal Verification of Mandatory access control for Privacy Cloud
    Zhu, Yi
    Zhu, Hong
    [J]. 2013 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), 2013, : 297 - 300
  • [9] Data-Driven Caching With Users' Content Preference Privacy in Information-Centric Networks
    Zhang, Xinyue
    Li, Hongning
    Wang, Jingyi
    Guo, Yuanxiong
    Pei, Qingqi
    Li, Pan
    Pan, Miao
    [J]. IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2021, 20 (09) : 5744 - 5753
  • [10] The effect of caching on a model of content and access provider revenues in information-centric networks
    Kocak, F.
    Kesidis, G.
    Pham, T. -M.
    Fdida, S.
    [J]. 2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 45 - 50