skip to main content
10.1145/3167132.3167358acmconferencesArticle/Chapter ViewAbstractPublication PagessacConference Proceedingsconference-collections
research-article

A distributed online certificate status protocol for named data networks

Published:09 April 2018Publication History

ABSTRACT

The Named Data Network (NDN) is a research activity towards the Internet of the Future, aiming to provide named content regardless location, application, or transport protocol. To secure content distribution, NDN uses a security model in which contents are digitally signed by their producers. Consumers must retrieve public keys to validate a content's signature, and need to check the validity status of those keys before using them. Traditional public key infrastructures use Certificate Revocation Lists (CRL) and the Online Certificate Status Protocol (OCSP) to disseminate key status information. However, such systems must be adapted to work on the NDN architecture. This paper proposes a replication system approach to disseminate key status information in NDN, regardless the key management system adopted. Replication techniques improve robustness, reduce convergence time, and improve key status availability throughout the network. Main results show a significant reduction in response time for consulting a key status, when compared to retrieving it from the original data producer.

References

  1. Tim Dierks. The transport layer security (TLS) protocol version 1.2. RFC 5246, 2008.Google ScholarGoogle Scholar
  2. Bengt Ahlgren, Christian Dannewitz, Claudio Imbrenda, Dirk Kutscher, and Borje Ohlman. A Survey of Information-Centric Networking. IEEE Communications Magazine, 50(7):26--36, 2012.Google ScholarGoogle ScholarCross RefCross Ref
  3. Van Jacobson, Diana K Smetters, James D Thornton, Michael F Plass, Nicholas H Briggs, and Rebecca L Braynard. Networking Named Content. In 5th international conference on Emerging networking experiments and technologies (ACM CoNEXT 2009), pages 1--12, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Yingdi Yu. Public Key Management in Named Data Networking. Technical Report NDN-0029, NDN, 2015.Google ScholarGoogle Scholar
  5. D Cooper, S Santesson, S Farrell, S Boeyen, R Housley, and W Polk. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280, 2008.Google ScholarGoogle Scholar
  6. Stefan Santesson, Michael Myers, Rich Ankney, Ambarish Malpani, Slava Galperin, and Carlisle Adams. X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP. RFC 2560, 2013.Google ScholarGoogle Scholar
  7. Jeremy Clark and Paul C van Oorschot. Sok: SSL and HTTPS: Revisiting past challenges and evaluating certificate trust model enhancements. In IEEE Symp. on Security and Privacy, pages 511--525. IEEE, 2013. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Dwaine Clarke, Jean-Emile Elien, Carl Ellison, Matt Fredette, Alexander Morcos, and Ronald L. Rivest. Certificate Chain Discovery in SPKI/SDSI. Journal of Computer Security, 9(4):285--322, 2001. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Yingdi Yu, Alexander Afanasyev, and Lixia Zhang. NDN DeLorean: An authentication system for data archives in named data networking. NDN, San Diego, CA, USA, Tech. Rep. NDN-0040, 2016.Google ScholarGoogle Scholar
  10. Paolo Gasti, Gene Tsudik, Ersin Uzun, and Lixia Zhang. DoS and DDoS in Named Data Networking. In 22nd Intl Conf on Computer Communication and Networks (ICCCN), pages 1--7. IEEE, 2013.Google ScholarGoogle Scholar
  11. Van Jacobson, Diana K. Smetters, James D. Thornton, Michael Plass, Nick Briggs, and Rebecca Braynard. Networking Named Content. Communications of the ACM, 55(1):117--124, January 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. Katie Shilton, Jeff Burke, KC Claffy, C Duan, and Lixia Zhang. A world on NDN: Affordances & implications of the named data networking future internet architecture. NDN, Technical Report NDN-0018, 2014.Google ScholarGoogle Scholar
  13. Diana Smetters and Van Jacobson. Securing network content, 2009.Google ScholarGoogle Scholar
  14. Giulia Mauri and Giacomo Verticale. Up-to-date key retrieval for information centric networking. Computer Networks, 112:1--11, 2017. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. Navin Budhiraja, Keith Marzullo, Fred B Schneider, and Sam Toueg. The Primary-Backup Approach. Distributed systems, 2:199--216, 1993. Google ScholarGoogle ScholarDigital LibraryDigital Library
  16. Spyridon Mastorakis, Alexander Afanasyev, Ilya Moiseenko, and Lixia Zhang. ndnSIM 2: An Updated NDN Simulator for NS-3. Technical Report NDN-0028, NDN, 2016.Google ScholarGoogle Scholar
  17. Neil Spring, Ratul Mahajan, and David Wetherall. Measuring ISP topologies with RocketFuel. ACM SIGCOMM Computer Communication Review, 32(4):133--145, 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library

Recommendations

Comments

Login options

Check if you have access through your login credentials or your institution to get full access on this article.

Sign in
  • Published in

    cover image ACM Conferences
    SAC '18: Proceedings of the 33rd Annual ACM Symposium on Applied Computing
    April 2018
    2327 pages
    ISBN:9781450351911
    DOI:10.1145/3167132

    Copyright © 2018 ACM

    Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    • Published: 9 April 2018

    Permissions

    Request permissions about this article.

    Request Permissions

    Check for updates

    Qualifiers

    • research-article

    Acceptance Rates

    Overall Acceptance Rate1,650of6,669submissions,25%

PDF Format

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader