Title :
Routing with confidence: supporting discretionary routing requirements in policy based networks
Author :
Kapadia, Apu ; Naldurg, Prasad ; Campbell, Roy H.
Author_Institution :
Dept. of Comput. Sci., Illinois Univ., Urbana, IL, USA
Abstract :
We propose a novel policy-based secure routing framework that extends the mandatory nature of network access-control policies and allows users to exercise discretionary control on what routes they choose in a given network. In contrast to existing research that focuses mainly on restricting network access based on user credentials, we present a model that allows users to specify discretionary constraints on path characteristics and discover routes based on situational trust attributes of routers in a network. In this context, we present three levels of trust-attribute certification based on inherent, consensus based, and inferred characteristics of routers. We also define a "confidence" measure that captures the "quality of protection" of a route with regard to various dynamic trust relationships that arise from this interaction between user preferences and network policy. Based on this measure, we show how to generate paths of highest confidence efficiently by using shortest path algorithms. We show how our model generalizes the notion of quality of protection (QoP) for secure routing and discuss how it can be applied to anonymous and privacy-aware routing, intrusion tolerant communication, and secure resource discovery for ubiquitous computing, high performance, and peer-to-peer environments.
Keywords :
authorisation; computer network management; telecommunication network routing; telecommunication security; ubiquitous computing; discretionary constraints; discretionary control; discretionary routing requirements; dynamic trust relationships; intrusion tolerant communication; network access-control policies; network routers; peer-to-peer environment; policy based networks; policy-based secure routing; privacy-aware routing; protection quality; secure resource discovery; shortest path algorithms; trust-attribute certification; ubiquitous computing; user credentials; user preferences; Access control; Certification; Communication system traffic control; Computer science; Intelligent networks; Laboratories; Protection; Routing; Traffic control; Ubiquitous computing;
Conference_Titel :
Policies for Distributed Systems and Networks, 2004. POLICY 2004. Proceedings. Fifth IEEE International Workshop on
Print_ISBN :
0-7695-2141-X
DOI :
10.1109/POLICY.2004.1309149