Title :
Towards an access control mechanism for wide-area publish/subscribe systems
Author_Institution :
Distributed Syst. Group, Technische Univ. Wien, Vienna, Austria
Abstract :
The publish/subscribe communication model is increasingly considered for implementing middleware infrastructures for widely distributed applications. Scalability issues and routing algorithms of such systems have recently been the focus of intensive research. So far little attention has been given to the security and management issues. In current publish/subscribe systems, malicious publishers can very easily insert bogus notifications which may propagated to a large number of subscribers. Moreover, there is no method to control what notifications the subscribers are authorized to receive. We describe a method to specify access control policy rules using expressions similar to subscription expressions. These policies define access rules for publish and subscribe functions and screening rules for notifications.
Keywords :
authorisation; client-server systems; distributed processing; security of data; access control; access rules; communication model; data security; middleware; publish subscribe communication; Access control; Communication system security; Internet; Joining processes; Large-scale systems; Middleware; Permission; Routing; Scalability; Subscriptions;
Conference_Titel :
Distributed Computing Systems Workshops, 2002. Proceedings. 22nd International Conference on
Print_ISBN :
0-7695-1588-6
DOI :
10.1109/ICDCSW.2002.1030820