DocumentCode :
2175241
Title :
Secure INtrusion-Tolerant Replication on the Internet
Author :
Cachin, Christian ; Poritz, Jonathan A.
Author_Institution :
Zurich Res. Lab., IBM Res., Ruschlikon, Switzerland
fYear :
2002
fDate :
2002
Firstpage :
167
Lastpage :
176
Abstract :
This paper describes a Secure INtrusion-Tolerant Replication Architecture (SINTRA) for coordination in asynchronous networks subject to Byzantine faults. SINTRA supplies a number of group communication primitives, such as binary and multi-valued Byzantine agreement, reliable and consistent broadcast, and an atomic broadcast channel. Atomic broadcast immediately provides secure state-machine replication. The protocols are designed for an asynchronous wide-area network, such as the Internet, where messages may be delayed indefinitely, the servers do not have access to a common clock, and up to one third of the servers may fail in potentially malicious ways. Security is achieved through the use of threshold public-key cryptography, in particular through a cryptographic common coin based on the Diffie-Hellman problem that underlies the randomized protocols in SINTRA. The implementation of SINTRA in Java is described and timing measurements are given for a test-bed of servers distributed over three continents. They show that extensive use of public-key cryptography does not impose a large overhead for secure coordination in wide-area networks.
Keywords :
Internet; Java; computer network reliability; protocols; public key cryptography; telecommunication security; Byzantine faults; Diffie-Hellman problem; Internet; Java; SINTRA; Secure Intrusion-Tolerant Replication Architecture; asynchronous networks; asynchronous wide-area network; atomic broadcast channel; group communication primitives; multi-valued Byzantine agreement; protocols; reliable consistent broadcast; secure state-machine replication; threshold public-key cryptography; timing measurements; Access protocols; Broadcasting; Clocks; Cryptographic protocols; IP networks; Internet; Network servers; Public key cryptography; Telecommunication network reliability; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2002. DSN 2002. Proceedings. International Conference on
Print_ISBN :
0-7695-1101-5
Type :
conf
DOI :
10.1109/DSN.2002.1028897
Filename :
1028897
Link To Document :
بازگشت