DocumentCode :
2538631
Title :
A security framework for service overlay networks: Access control
Author :
Kurian, Jinu ; Sarac, Kamil
Author_Institution :
Dept. of Comput. Sci., Univ. of Texas at Dallas, Richardson, TX
fYear :
2008
fDate :
8-11 Sept. 2008
Firstpage :
412
Lastpage :
419
Abstract :
Service overlay networks (SONs) have recently been proposed to support various value-added services including multicast, resilient routing, QoS support, and DoS resistant communication in the Internet. Access control plays an important role for various SON applications yet most SON proposals do not consider access control or assume that it is a pre-existing service. The lack of a proper access control mechanism may introduce security or efficiency problems for various SON applications. In this paper, we present a scalable, distributed access control scheme with very low state information required to be maintained at the SON nodes. Using this service, a SON access node can decide if an end userpsilas traffic should be accepted into the SON overlay for processing and forwarding towards its intended destination. We present our scheme and evaluate it via a combination of formal verification, security analysis, and an experimental evaluation work on its practicality.
Keywords :
Internet; authorisation; multicast communication; quality of service; telecommunication network routing; telecommunication security; telecommunication traffic; DoS resistant communication; Internet; QoS support; distributed access control scheme; formal verification; multicast communication; network traffic; resilient routing; security framework; service overlay network; value-added service; Access control; Application software; Authentication; Computer science; Computer security; Forward contracts; IP networks; Proposals; Routing; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Broadband Communications, Networks and Systems, 2008. BROADNETS 2008. 5th International Conference on
Conference_Location :
London
Print_ISBN :
978-1-4244-2391-0
Electronic_ISBN :
978-1-4244-2392-7
Type :
conf
DOI :
10.1109/BROADNETS.2008.4769117
Filename :
4769117
Link To Document :
بازگشت