• DocumentCode
    2175241
  • Title

    Secure INtrusion-Tolerant Replication on the Internet

  • Author

    Cachin, Christian ; Poritz, Jonathan A.

  • Author_Institution
    Zurich Res. Lab., IBM Res., Ruschlikon, Switzerland
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    167
  • Lastpage
    176
  • Abstract
    This paper describes a Secure INtrusion-Tolerant Replication Architecture (SINTRA) for coordination in asynchronous networks subject to Byzantine faults. SINTRA supplies a number of group communication primitives, such as binary and multi-valued Byzantine agreement, reliable and consistent broadcast, and an atomic broadcast channel. Atomic broadcast immediately provides secure state-machine replication. The protocols are designed for an asynchronous wide-area network, such as the Internet, where messages may be delayed indefinitely, the servers do not have access to a common clock, and up to one third of the servers may fail in potentially malicious ways. Security is achieved through the use of threshold public-key cryptography, in particular through a cryptographic common coin based on the Diffie-Hellman problem that underlies the randomized protocols in SINTRA. The implementation of SINTRA in Java is described and timing measurements are given for a test-bed of servers distributed over three continents. They show that extensive use of public-key cryptography does not impose a large overhead for secure coordination in wide-area networks.
  • Keywords
    Internet; Java; computer network reliability; protocols; public key cryptography; telecommunication security; Byzantine faults; Diffie-Hellman problem; Internet; Java; SINTRA; Secure Intrusion-Tolerant Replication Architecture; asynchronous networks; asynchronous wide-area network; atomic broadcast channel; group communication primitives; multi-valued Byzantine agreement; protocols; reliable consistent broadcast; secure state-machine replication; threshold public-key cryptography; timing measurements; Access protocols; Broadcasting; Clocks; Cryptographic protocols; IP networks; Internet; Network servers; Public key cryptography; Telecommunication network reliability; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2002. DSN 2002. Proceedings. International Conference on
  • Print_ISBN
    0-7695-1101-5
  • Type

    conf

  • DOI
    10.1109/DSN.2002.1028897
  • Filename
    1028897