DocumentCode :
3409581
Title :
Internet Unite-and-Conquer architecture
Author :
Karimi, Kamyab ; Hauser, Carl
fYear :
2013
fDate :
9-12 Dec. 2013
Firstpage :
219
Lastpage :
230
Abstract :
This paper presents UnC (Unite and Conquer), a network architecture for the Internet that provides a self-certifying mechanism to reliably distribute, retrieve, and authenticate the public keys across the Internet. UnC may be used in parallel with the existing Public Key Infrastructure (PKI) ecosystem to provide an additional validation step for certificates offered by the PKI model. Leveraging the properties of the Internet infrastructure combined with cooperation from other hosts that act as notaries, UnC attests to the stability of certificates in time and space. By uniting notaries, UnC overwhelms and outnumbers attackers, and it uses this unity to conquer attack plots. Unlike existing proposals aimed to incorporate accountability into the Internet, UnC does not require external certificate hierarchies or certificate authorities to manage digital certificates. UnC can also be integrated in the Secure DNS (DNSSEC) protocols as well as the Secure BGP (S-BGP) protocol to eliminate the need for external key structures while protecting bindings between the entities and their IP addresses, and the integrity of the routing tables between Autonomous Systems. This paper describes the UnC architecture in detail, including the actions of each different kind of participant. It describes how UnC deals with well-known attack models, which are readily available on the Internet.The major contribution of this work is to open up a new door for the research community to exploit the predominance of good nodes over malicious ones in order to enhance the security of the PKI ecosystem and the Internet.
Keywords :
Internet; public key cryptography; DNSSEC protocols; Internet unite-and-conquer architecture; PKI model; S-BGP protocol; UnC architecture; public key infrastructure ecosystem; secure BGP protocol; secure DNS protocols; self-certifying mechanism; Artificial neural networks; IP networks; Indexes; Internet; Public key; Publishing; Internet architecture; PKI infrastructure; geographic clusters; notary nodes; security; self-certifying addresses;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2013 8th International Conference for
Conference_Location :
London
Type :
conf
DOI :
10.1109/ICITST.2013.6750195
Filename :
6750195
Link To Document :
بازگشت