• DocumentCode
    2651442
  • Title

    Distributed Overlay Construction to Support Policy-Based Access Control

  • Author

    Ko, Bong Jun ; Wong, Starsky H Y ; Lee, Kang-Won ; Chau, Chi-Kin

  • Author_Institution
    IBM T. J. Watson Res. Center, Hawthorne, NY, USA
  • fYear
    2011
  • fDate
    6-8 June 2011
  • Firstpage
    49
  • Lastpage
    56
  • Abstract
    Overlay networks have been studied extensively in recent years as a flexible means to improving the reliability, resiliency, and performance of many networking applications. In this paper we present a novel use of overlay networks and distributed mechanisms to construct them for handling information assurance issues in networking systems. The problem is explored in the context of constructing an overlay that satisfies a given set of access control policies in decentralized information sharing systems. We formulate a new graph-theoretic optimization problem of constructing a minimum policy-compatible graph, which is NP-complete. We provide efficient centralized and fully-distributed heuristics, and prove the convergence property of the distributed process. Our simulation study with synthetic and empirical data set shows that our methods result in the performance (in terms of total number of links) very close to the optimal case (within 3%) for small input, and that they can reduce the number by up to 30% compared to a method based on minimum spanning tree algorithm for larger data set.
  • Keywords
    authorisation; computational complexity; computer network security; optimisation; trees (mathematics); NP-complete problem; distributed overlay network; graph-theoretic optimization problem; minimum policy-compatible graph; minimum spanning tree algorithm; networking system; policy-based access control; Access control; Cost function; Organizations; Polynomials; Sensors; Topology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks (POLICY), 2011 IEEE International Symposium on
  • Conference_Location
    Pisa
  • Print_ISBN
    978-1-4244-9879-6
  • Electronic_ISBN
    978-0-7695-4330-7
  • Type

    conf

  • DOI
    10.1109/POLICY.2011.46
  • Filename
    5976795