DocumentCode
2538631
Title
A security framework for service overlay networks: Access control
Author
Kurian, Jinu ; Sarac, Kamil
Author_Institution
Dept. of Comput. Sci., Univ. of Texas at Dallas, Richardson, TX
fYear
2008
fDate
8-11 Sept. 2008
Firstpage
412
Lastpage
419
Abstract
Service overlay networks (SONs) have recently been proposed to support various value-added services including multicast, resilient routing, QoS support, and DoS resistant communication in the Internet. Access control plays an important role for various SON applications yet most SON proposals do not consider access control or assume that it is a pre-existing service. The lack of a proper access control mechanism may introduce security or efficiency problems for various SON applications. In this paper, we present a scalable, distributed access control scheme with very low state information required to be maintained at the SON nodes. Using this service, a SON access node can decide if an end userpsilas traffic should be accepted into the SON overlay for processing and forwarding towards its intended destination. We present our scheme and evaluate it via a combination of formal verification, security analysis, and an experimental evaluation work on its practicality.
Keywords
Internet; authorisation; multicast communication; quality of service; telecommunication network routing; telecommunication security; telecommunication traffic; DoS resistant communication; Internet; QoS support; distributed access control scheme; formal verification; multicast communication; network traffic; resilient routing; security framework; service overlay network; value-added service; Access control; Application software; Authentication; Computer science; Computer security; Forward contracts; IP networks; Proposals; Routing; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Broadband Communications, Networks and Systems, 2008. BROADNETS 2008. 5th International Conference on
Conference_Location
London
Print_ISBN
978-1-4244-2391-0
Electronic_ISBN
978-1-4244-2392-7
Type
conf
DOI
10.1109/BROADNETS.2008.4769117
Filename
4769117
Link To Document