• DocumentCode
    2538631
  • Title

    A security framework for service overlay networks: Access control

  • Author

    Kurian, Jinu ; Sarac, Kamil

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Texas at Dallas, Richardson, TX
  • fYear
    2008
  • fDate
    8-11 Sept. 2008
  • Firstpage
    412
  • Lastpage
    419
  • Abstract
    Service overlay networks (SONs) have recently been proposed to support various value-added services including multicast, resilient routing, QoS support, and DoS resistant communication in the Internet. Access control plays an important role for various SON applications yet most SON proposals do not consider access control or assume that it is a pre-existing service. The lack of a proper access control mechanism may introduce security or efficiency problems for various SON applications. In this paper, we present a scalable, distributed access control scheme with very low state information required to be maintained at the SON nodes. Using this service, a SON access node can decide if an end userpsilas traffic should be accepted into the SON overlay for processing and forwarding towards its intended destination. We present our scheme and evaluate it via a combination of formal verification, security analysis, and an experimental evaluation work on its practicality.
  • Keywords
    Internet; authorisation; multicast communication; quality of service; telecommunication network routing; telecommunication security; telecommunication traffic; DoS resistant communication; Internet; QoS support; distributed access control scheme; formal verification; multicast communication; network traffic; resilient routing; security framework; service overlay network; value-added service; Access control; Application software; Authentication; Computer science; Computer security; Forward contracts; IP networks; Proposals; Routing; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband Communications, Networks and Systems, 2008. BROADNETS 2008. 5th International Conference on
  • Conference_Location
    London
  • Print_ISBN
    978-1-4244-2391-0
  • Electronic_ISBN
    978-1-4244-2392-7
  • Type

    conf

  • DOI
    10.1109/BROADNETS.2008.4769117
  • Filename
    4769117