Title :
Gothic: a group access control architecture for secure multicast and anycast
Author :
Judge, Paul ; Ammar, Mostafa
Author_Institution :
Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
Abstract :
Multicast and anycast have received considerable attention due to their ability to support networked services. There are distinct and significant security vulnerabilities in both the multicast and anycast model including denial of service, theft or service, eavesdropping, and masquerading. The multicast problem requires a secure IGMP. The anycast problem requires secure anycast server advertisements. We generalize these two problems into a problem of group access control and propose Gothic, a complete architecture for providing group access control. Gothic centers around a novel authorization architecture. This is complemented by a proposal for a group policy management system that allows the group owner to be authenticated before being allowed to specify the group access rights. This system can be applied to other works that involve group policy. We show how Gothic operates in a number of environments including application-layer multicast, source-specific multicast, application-layer anycast and global IP-anycast. We evaluate the security and scalability of the architecture and show that it improves scalability over previous solutions while maintaining or increasing the level of security. We also propose methods of integrating Gothic with the group key management system and content distribution tree. We propose and evaluate a group access control aware group key management technique that leverages the existence of a group access control system to substantially reduce overhead.
Keywords :
Internet; message authentication; multicast communication; telecommunication control; telecommunication security; Gothic; Internet; application-layer anycast; application-layer multicast; architecture scalability; architecture security; authorization architecture; content distribution tree; denial of service; eavesdropping; global IP-anycast; group access control architecture; group access rights; group key management system; group policy management system; masquerading; networked services; overhead reduction; secure IGMP; secure anycast; secure anycast server advertisements; secure multicast; security vulnerabilities; source-specific multicast; theft or service; Access control; Computer architecture; Computer crime; Cryptography; Educational institutions; Multicast protocols; Network servers; Routing protocols; Scalability; Security;
Conference_Titel :
INFOCOM 2002. Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE
Print_ISBN :
0-7803-7476-2
DOI :
10.1109/INFCOM.2002.1019406