• DocumentCode
    180959
  • Title

    Establishing Secure Interactions across Distributed Applications in Satellite Clusters

  • Author

    Pradhan, Subrata ; Emfinger, William ; Dubey, Anamika ; Otte, William R. ; Balasubramanian, Daniel ; Gokhale, Aniruddha ; Karsai, Gabor ; Coglio, Alessandro

  • Author_Institution
    ISIS/EECS, Vanderbilt Univ., Nashville, TN, USA
  • fYear
    2014
  • fDate
    24-26 Sept. 2014
  • Firstpage
    67
  • Lastpage
    74
  • Abstract
    Recent developments in small satellites have led to an increasing interest in building satellite clusters as open systems that provide a "cluster-as-a-service" in space. Since applications with different security classification levels must be supported in these open systems, the system must provide strict information partitioning such that only applications with matching security classifications interact with each other. The anonymous publish/subscribe communication pattern is a powerful interaction abstraction that has enjoyed great success in previous space software architectures, such as NASA\´s Core Flight Executive. However, the difficulty is that existing solutions that support anonymous publish/subscribe communication, such as the OMG Data Distribution Service (DDS), do not support information partitioning based on security classifications, which is a key requirement for some systems. This paper makes two contributions to address these limitations. First, we present a transport mechanism called Secure Transport that uses a lattice of labels to represent security classifications and enforces Multi-Level Security (MLS) policies to ensure strict information partitioning. Second, we present a novel discovery service that allows us to use an existing DDS implementation with our custom transport mechanism to realize a publish/subscribe middleware with information partitioning based on security classifications of applications. We also include an evaluation of our solution in the context of a use case scenario.
  • Keywords
    aerospace computing; artificial satellites; middleware; open systems; pattern classification; security of data; software architecture; DDS; MLS; NASA core flight executive; OMG data distribution service; anonymous publish-subscribe communication pattern; cluster-as-a-service; discovery service; distributed applications; information partitioning; interaction abstraction; multilevel security policy; open systems; publish-subscribe middleware; satellite clusters; secure interactions; secure transport mechanism; security classification levels; space software architectures; Computer architecture; Middleware; Peer-to-peer computing; Satellites; Security; Servers; Standards; Multi-Level Security; OMG Data Distribution Service; Secure Discovery; Secure Publish/Subscribe Middleware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Space Mission Challenges for Information Technology (SMC-IT), 2014 IEEE International Conference on
  • Conference_Location
    Laurel MD
  • Type

    conf

  • DOI
    10.1109/SMC-IT.2014.17
  • Filename
    6979147