Gothic: A Group Access Control Architecture for Secure Multicast and Anycast
نویسندگان
چکیده
Multicast and anycast have received considerable attention due to their ability to support networked services. There are distinct and significant security vulnerabilities in both the multicast and anycast model including denial of service, theft of service, eavesdropping, and masquerading. The multicast problem requires a secure IGMP. The anycast problem requires secure anycast server advertisements. We generalize these two problems into a problem of group access control and propose Gothic, a complete architecture for providing group access control. Gothic centers around a novel authorization architecture. This is complemented by a proposal for a group policy management system that allows the group owner to be authenticated before being allowed to specify the group access rights. This system can be applied to other works that involve group policy. We show how Gothic operates in a number of environments including application-layer multicast, source-specific multicast, application-layer anycast and global IP-anycast. We evaluate the security and scalability of the architecture and show that it improves scalability over previous solutions while maintaining or increasing the level of security. We also propose methods of integrating Gothic with the group key management system and content distribution tree. We propose and evaluate a group access control aware group key management technique that leverages the existence of a group access control system to substantially reduce overhead.
منابع مشابه
A Flexible and Secure Multicast Architecture for ATM Networks
We describe our unifying architecture for multipoint-to-multipoint communications in ATM networks which meets the diverse requirement of group communications and permit a large degree of control on the multicast group. With an integrated use of a name space, the scheme allows scalable extension to large scale wide area multicast communications. We also enable exible control on routeing architec...
متن کاملThe Use of Ip-anycast for Building Efficient Multicast Trees
In this paper, we show that substantial improvement in multicast performance and reliability can be achieved by regarding a multicast group as a network region and using anycast to access it along the shortest path. We introduce the anycast-based tree (ABT), a novel architecture for building efficient shared multicast trees. ABT is a noncore tree; thus, it does not suffer from the traditional p...
متن کاملFlexible Secure Multicasting in Active Networks
In this paper we describe an alternative, exible approach to multicast security in active networks. Traditional schemes for securing multicast communication have key management and scalability problems for many typical applications. In addition, traditional mechanisms are not capable of expressing exible, situational security policies for multicast sessions and participants. Our scheme exploits...
متن کاملMulti-shared-trees based multicast routing control protocol using anycast selection
A novel internet multicast routing protocol is presented to possess efficiency and effectiveness for multicast packet routing with short delay, high throughput, resource utilization and scalability for a single multicast group g. The protocol has two features: (1) Multiple Shared-Trees (MST) are configured to provide efficient, dynamic and quality multicast routing; (2) Anycasting approach is a...
متن کاملIP Anycast Architecture
This paper illustrates the methodology and architecture for network addressing and routing in which datagram packets routed through mathematical topological nearest node in a cluster of potential receivers that are being identified by equivalent destination address space. Mathematical framework is proposed to improve the Anycast usage. KeywordsIP Anycast, Multicast, Mobile IPV6, Addressing, Rou...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2002