• DocumentCode
    1807000
  • Title

    DToken: A Lightweight and Traceable Delegation Architecture for Distributed Systems

  • Author

    Yang, Erica Y. ; Matthews, Brian

  • Author_Institution
    Rutherford Appleton Lab. (RAL), Sci. & Technol. Facilities Council (STFC), Didcot, UK
  • fYear
    2009
  • fDate
    27-30 Sept. 2009
  • Firstpage
    107
  • Lastpage
    116
  • Abstract
    Several major techniques have been proposed to address delegation problems in distributed computing environments of various scales, ranging from LAN, WAN, to the Internet. One of the major characteristics of existing public key cryptography based delegation mechanisms is their use of a fresh key pair every step along the delegation chain. This has led to a range of open issues, including a non-negligible performance overhead imposed by using a fresh key pair in proxy credentials; the lack of traceability of the principals in a delegation chain; and the complexity of managing the dynamically created key pairs in the distributed environment. This paper focuses on the architectural issues of delegation. We propose a new delegation architecture, called DToken, that takes advantage of the PKI. DToken is lightweight as it eliminates the use of freshly generated key pairs in a distributed setting. DToken is also traceable because the identity of the principals in a delegation chain is preserved by cryptographically verifiable mechanisms. A preliminary evaluation demonstrates that DToken outperforms the popular delegation solution of proxy certificate. In a single-level delegation, the cost of creating a DToken, the major cost of delegation, is roughly 1/3, 1/5, and 1/10 of that of creating a proxy certificate when the certificate key size is 512, 1024, and 2048 bits, respectively.
  • Keywords
    distributed processing; public key cryptography; DToken architecture; Internet; LAN; WAN; cryptography verifiable mechanisms; distributed computing environments; distributed systems; grid delegation; grid key management; proxy certificate; public key cryptography; single-level delegation mechanism; traceable delegation architecture; Authorization; Computer architecture; Costs; Councils; Decision support systems; Distributed computing; Local area networks; Public key cryptography; Security; Wide area networks; Grid delegation; Grid key management; delegation architecture; lightweight delegation; traceable delegation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Reliable Distributed Systems, 2009. SRDS '09. 28th IEEE International Symposium on
  • Conference_Location
    Niagara Falls, NY
  • ISSN
    1060-9857
  • Print_ISBN
    978-0-7695-3826-6
  • Type

    conf

  • DOI
    10.1109/SRDS.2009.31
  • Filename
    5283397