|
ABSTRACT
Secure reliable group communication protocols can facilitate the development of survivable distributed systems that are able to remain correct and reliable despite intrusions that cause some nodes to behave in an arbitrary or malicious manner. However, the development of such protocols is itself difficult, and prior systems have exhibited high overheads, primarily due to the cost of digital signatures. The SecureRing group communication system provides secure, reliable, totally-ordered message delivery and group membership services despite the malicious corruption of a constant fraction of the processors within the system. The network is assumed not to partition, and persistent communication faults are handled as processor faults. The SecureRing message delivery protocol makes use of message digests in a signed token to allow a single digital signature to cover multiple messages, and to avoid the need for multiple rounds of message exchange in normal operation. While these techniques mean that messages are not authenticated in real time, they enable the SecureRing protocols to achieve high throughput and reasonable latency.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
 |
2
|
|
| |
3
|
|
 |
4
|
|
| |
5
|
DIFFIE,W.AND HELLMAN, M. 1976. New directions in cryptography. IEEE Trans. Inf. Theory IT- 22, 6 (Nov.), 644-654.
|
| |
6
|
ELLISON,R.J.,FISHER, D. A., LINGER,R.C.,LIPSON,H.F.,LONGSTAFF,T.,AND MEAD, N. R. 1997. Survivable network systems: An emerging discipline. Tech. Rep. CMU/SEI-97-TR-013 (Nov.), Software Engineering Institute, Carnegie Mellon University.
|
 |
7
|
|
| |
8
|
|
| |
9
|
KIHLSTROM,K.P.,MOSER,L.E.,AND MELLIAR-SMITH, P. M. 1997. Solving consensus in a Byzantine environment using an unreliable fault detector. In Proceedings of the International Conference on Principles of Distributed Systems (Chantilly, France, Dec.), 61-75.
|
| |
10
|
|
| |
11
|
LACY,J.B.,MITCHELL,D.P.,AND SCHELL, W. M. 1993. CryptoLib: Cryptography in software. In Proceedings of the 4th USENIX Security Workshop (Santa Clara, CA, Oct.), 1-17.
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
| |
15
|
|
| |
16
|
|
 |
17
|
|
| |
18
|
MOSER, L. E., MELLIAR-SMITH,P.M.,AND NARASIMHAN, N. 2000. The Secure Group communication system. In Proceedings of the IEEE Information Survivability Conference (Hilton Head, SC, Jan. 2000), 256-270.
|
| |
19
|
|
| |
20
|
NARASIMHAN, P., MOSER,L.E.,AND MELLIAR-SMITH, P. M. 1996. Message packing as a performance enhancement strategy with application to the Totem protocols. In Proceedings of the IEEE Global Telecommunications Conference (London, UK, Nov. 1996), 649-653.
|
| |
21
|
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. 1995. Secure hash standard. Federal Information Processing Standards Publication 180-1.
|
 |
22
|
|
| |
23
|
|
| |
24
|
|
| |
25
|
|
| |
26
|
RIVEST, R. L. 1992. The MD5 message digest algorithm. Internet Activities Board.
|
 |
27
|
|
INDEX TERMS
Primary Classification:
C.
Computer Systems Organization
C.2
COMPUTER-COMMUNICATION NETWORKS
C.2.0
General
Subjects:
Security and protection (e.g., firewalls)
Additional Classification:
D.
Software
D.4
OPERATING SYSTEMS
D.4.5
Reliability
Subjects:
Fault-tolerance
D.4.6
Security and Protection
Subjects:
Invasive software (e.g., viruses, worms, Trojan horses)
K.
Computing Milieux
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
K.6.5
Security and Protection (D.4.6, K.4.2)
Subjects:
Invasive software (e.g., viruses, worms, Trojan horses)
General Terms:
Reliability,
Security
Keywords:
Byzantine faults,
group communication,
intrusion,
partial synchrony,
state machine replication,
survivability
REVIEW
"Eliezer Dekel : Reviewer"
The SecureRing group communication system, developed by the authors at the University of California Santa Barbara, is described in this paper. SecureRing can facilitate the development of survivable distributed systems by providing secure, reliabl
more...
Peer to Peer - Readers of this Article have also read:
-
Web application security assessment by fault injection and behavior monitoring
Proceedings of the 12th international conference on World Wide Web
Yao-Wen Huang
, Shih-Kun Huang
, Tsung-Po Lin
, Chung-Hung Tsai
-
Inferring constraints from multiple snapshots
ACM Transactions on Graphics (TOG)
12, 4
David Kurlander
, Steven Feiner
-
Data structures for quadtree approximation and compression
Communications of the ACM
28, 9
Hanan Samet
-
A hierarchical single-key-lock access control using the Chinese remainder theorem
Proceedings of the 1992 ACM/SIGAPP Symposium on Applied computing
Kim S. Lee
, Huizhu Lu
, D. D. Fisher
-
The GemStone object database management system
Communications of the ACM
34, 10
Paul Butterworth
, Allen Otis
, Jacob Stein
|