• DocumentCode
    1465909
  • Title

    A Policy Enforcing Mechanism for Trusted Ad Hoc Networks

  • Author

    Xu, Gang ; Borcea, Cristian ; Iftode, Liviu

  • Author_Institution
    AT&T, Inc., Middletown, NJ, USA
  • Volume
    8
  • Issue
    3
  • fYear
    2011
  • Firstpage
    321
  • Lastpage
    336
  • Abstract
    To ensure fair and secure communication in Mobile Ad hoc Networks (MANETs), the applications running in these networks must be regulated by proper communication policies. However, enforcing policies in MANETs is challenging because they lack the infrastructure and trusted entities encountered in traditional distributed systems. This paper presents the design and implementation of a policy enforcing mechanism based on Satem, a kernel-level trusted execution monitor built on top of the Trusted Platform Module. Under this mechanism, each application or protocol has an associated policy. Two instances of an application running on different nodes may engage in communication only if these nodes enforce the same set of policies for both the application and the underlying protocols used by the application. In this way, nodes can form trusted application-centric networks. Before allowing a node to join such a network, Satem verifies its trustworthiness of enforcing the required set of policies. Furthermore, Satem protects the policies and the software enforcing these policies from being tampered with. If any of them is compromised, Satem disconnects the node from the network. We demonstrate the correctness of our solution through security analysis, and its low overhead through performance evaluation of two MANET applications.
  • Keywords
    mobile ad hoc networks; mobile computing; protocols; telecommunication security; Satem; mobile ad hoc networks; policy enforcing mechanism; secure communication; trusted ad hoc networks; trusted execution monitor; trusted platform module; Ad hoc networks; Application software; Computer networks; Computer science; Mobile ad hoc networks; Mobile communication; Monitoring; Peer to peer computing; Protection; Protocols; Trusted computing; ad hoc networks; mobile computing.;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2010.11
  • Filename
    5444889