• DocumentCode
    1630075
  • Title

    Differentially secure multicasting and its implementation methods

  • Author

    Holeman, S. ; Manimaran, G. ; Davis, J.

  • Author_Institution
    Dependable Comput. & Networking Lab., Iowa State Univ., Ames, IA, USA
  • fYear
    2001
  • fDate
    6/23/1905 12:00:00 AM
  • Firstpage
    212
  • Lastpage
    217
  • Abstract
    Though the areas of secure multicast group architecture, key distribution and sender authentication are under scrutiny, one topic that has not been explored is how to integrate these with multilevel security. Multilevel security is the ability to distinguish subjects according to classification levels, which determines to what degree they can access confidential objects. In the case of groups, this means that some members can exchange messages at a higher sensitivity level than others. The Bell-La Padula model outlines the rules of these multilevel accesses (see Bell, D. and La Padula, L., MITRE Report, M74-244, MTR 2547 v2, 1973). In multicast groups that employ multilevel security, some of these rules are not desirable, so a modified set of rules is developed and is termed differential security. Also, this paper proposes three methods to set up a differentially secure multicast group: (1) naive approach, (2) multiple tree differential security (DiffSec) approach, and (3) single DiffSec tree approach. Our simulation studies show that both single and multiple DiffSec tree approaches offer similar performance in terms of bandwidth consumption, which is significantly better than that of the naive approach. We also discuss the suitability of the schemes, taking into account scalability and implementation issues
  • Keywords
    Internet; cryptography; message authentication; multicast communication; telecommunication security; trees (mathematics); Internet; bandwidth consumption; cryptographic key distribution; differentially secure multicasting; multicast groups; multilevel security; multiple tree; resource consumption; sender authentication; single tree; Bandwidth; Computer networks; Cryptography; Distributed computing; Information systems; Laboratories; Multicast communication; Multilevel systems; Scalability; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2001. Proceedings. Tenth International Conference on
  • Conference_Location
    Scottsdale, AZ
  • ISSN
    1095-2055
  • Print_ISBN
    0-7803-7128-3
  • Type

    conf

  • DOI
    10.1109/ICCCN.2001.956244
  • Filename
    956244