{"title":"Public Key Infrastructure for Named Data Networks","authors":"Ranit Chatterjee, S. Ruj, S. Bit","doi":"10.1145/3369740.3369790","DOIUrl":null,"url":null,"abstract":"Named Data Networking (NDN) is a proposed Internet architecture which changes the basic model of network communication. Instead of host-centric (IP based) addressing of the present day Internet architecture, NDN is primarily a data-centric design. The main design principle of NDN is securing the data rather than securing the communication channel. In this paper we show some limitations of NDN's Trust based security framework and propose anew public key management scheme. Our design is motivated by the concept of Google's Certificate Transparency. By using a Merkle Patricia Trie to store certificates, we are not only able to perform efficient verification of certificates, but also ensure that certificates are not tampered with. We believe this will prevent dangerous frauds on certificate authorities that have taken place in the recent past.","PeriodicalId":240048,"journal":{"name":"Proceedings of the 21st International Conference on Distributed Computing and Networking","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-01-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 21st International Conference on Distributed Computing and Networking","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3369740.3369790","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Named Data Networking (NDN) is a proposed Internet architecture which changes the basic model of network communication. Instead of host-centric (IP based) addressing of the present day Internet architecture, NDN is primarily a data-centric design. The main design principle of NDN is securing the data rather than securing the communication channel. In this paper we show some limitations of NDN's Trust based security framework and propose anew public key management scheme. Our design is motivated by the concept of Google's Certificate Transparency. By using a Merkle Patricia Trie to store certificates, we are not only able to perform efficient verification of certificates, but also ensure that certificates are not tampered with. We believe this will prevent dangerous frauds on certificate authorities that have taken place in the recent past.