Title :
Trusted P2P computing environments with role-based access control
Author :
Park, J.S. ; An, G. ; Chandra, D.
Author_Institution :
Lab. for Appl. Inf. Security Technol., Syracuse Univ., LAIST, NY
fDate :
3/1/2007 12:00:00 AM
Abstract :
A P2P computing environment can be an ideal platform for resource-sharing services in an organisation if it provides trust mechanisms. Current P2P technologies offer content-sharing services for non-sensitive public domains in the absence of trust mechanisms. The lack of sophisticated trust mechanisms in the current P2P environment has become a serious constraint for broader applications of the technology although it has great potential. Therefore in this work an approach for securing transactions in the P2P environment is introduced, and ways to incorporate an effective and scalable access control mechanism - role-based access control (RBAC) - into current P2P computing environments has been investigated, proposing two different architectures: requesting peer-pull (RPP) and ultrapeer-pull (UPP) architectures. To provide a mobile, session-based authentication and RBAC, especially in the RPP architecture, lightweight peer certificates (LWPCs) are developed. Finally, to prove the feasibility of the proposed ideas, the RPP and UPP RBAC architectures are implemented and their scalability and performance are evaluated
Keywords :
authorisation; peer-to-peer computing; P2P computing environments; P2P technology; access control mechanism; content-sharing services; lightweight peer certificates; nonsensitive public domains; requesting peer-pull architecture; resource-sharing services; role-based access control; session-based authentication; trust mechanisms; ultrapeer-pull architecture;
Journal_Title :
Information Security, IET
DOI :
10.1049/iet-ifs:20060084