ACM Home Page
Please provide us with feedback. Feedback
Parameterized access control: from design to prototype
Full text PdfPdf (146 KB)
Source Proceedings of the 4th international conference on Security and privacy in communication netowrks table of contents
Istanbul, Turkey
SESSION: Miscellaneous table of contents
Article No. 35  
Year of Publication: 2008
ISBN:978-1-60558-241-2
Authors
Ashish Gehani  SRI International, Menlo Park, CA
Surendar Chandra  University of Notre Dame, Notre Dame, IN
Sponsors
: Create-Net
: INRIA
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 0,   Downloads (12 Months): 20,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1460877.1460922
What is a DOI?

ABSTRACT

Peer-to-peer overlays provide a substrate well suited to building distributed storage systems. Applications that use the infrastructure need the ability to control access to their data. However, traditional authorization services were not designed to operate in the face of network partitions, malicious nodes, and on an Internet-wide scale.

We describe the implementation of the Decentralized Authentication and Authorization Layer (DAAL), a mechanism to leverage the storage functionality of the overlay and obviate the need for an online, centralized access control service. The system can efficiently identify malicious nodes and continue to operate correctly when an arbitrary, predefined fraction of the network is unreachable (as occurs during an attack against the routing infrastructure or during a distributed denial-of-service attack).

DAAL melds the access request efficiency of capability-based systems with the revocation power of reference monitor-based access control lists. It avoids the use of distributed leases as they create a vulnerability window during which there is a gap between the security policy and configuration. Actualizing the design can be challenging. Hence, we describe the protocol details and how they can be abstracted behind a minimal, intuitive application programming interface. As a proof of concept, we implemented DAAL as a Java prototype on a 200-node peer-to-peer overlay distributed across the world.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
Steven M. Bellovin and Michael Merritt, Limitations of the Kerberos Authentication System, USENIX Conference, 1991.
 
3
 
4
A. Duffy and T. Dowling, An Object Oriented Approach to an Identity Based Encryption Cryptosystem, 8th IASTED International Conference on Software, 2004.
 
5
 
6
Ashish Gehani and Surendar Chandra, Parameterizing Access Control for Heterogeneous Peer-to-Peer Applications, 3rd International Conference on Security and Privacy in Communication Networks (SecureComm), IEEE Computer Society, 2007.
 
7
Eu-Jin Goh, Hovav Shacham, Nagendra Modadugu and Dan Boneh, SiRiUS: Securing Remote Untrusted Storage, Network and Distributed Systems Security Symposium, 2003.
8
 
9
A. Hisgen, A. Birrell, T. Mann, M. Schroeder and G. Swart, Availability and Consistency Tradeoffs in the Echo Distributed File System, 2nd IEEE Workshop on Workstation Operating Systems, 1989.
 
10
 
11
Butler W. Lampson, Protection, 5th Princeton Symposium on Information Sciences and Systems, 1971.
12
 
13
 
14
15
16
17
 
18
 
19
J. G. Steiner, B. C. Neuman and J. I. Schiller, Kerberos: An Authentication Service for Open Network Systems, Winter Usenix Conference, 1988.
20
 
21

Collaborative Colleagues:
Ashish Gehani: colleagues
Surendar Chandra: colleagues