Secure Host Identity Delegation for Mobility

S. Herborn, A. Huber, R. Boreli, A. Seneviratne
{"title":"Secure Host Identity Delegation for Mobility","authors":"S. Herborn, A. Huber, R. Boreli, A. Seneviratne","doi":"10.1109/COMSWA.2007.382596","DOIUrl":null,"url":null,"abstract":"We develop a scheme for host identity delegation based on the Host Identity Protocol (HIP). We show how this scheme can be applied to enable the movement of communication sessions between devices e.g. in a Personal Area Network (PAN), or to securely and seamlessly insert any number of service proxies in between session endpoints e.g. to adapt data to suit different devices in a PAN. Identities are securely delegated by relaying HIP signalling messages to the device that owns the private key. This avoids security issues caused by dissemination of private keys. This also ensures that delegated endpoint identities are instantly and permanently revocable by the original device which remains in full control of the private key used to authorize use of the identity. We show that the delegation process introduces minimal additional signalling, and present results of evaluation of a prototype which show the scheme results in no detriment to the performance of HIP.","PeriodicalId":191295,"journal":{"name":"2007 2nd International Conference on Communication Systems Software and Middleware","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-07-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 2nd International Conference on Communication Systems Software and Middleware","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMSWA.2007.382596","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

We develop a scheme for host identity delegation based on the Host Identity Protocol (HIP). We show how this scheme can be applied to enable the movement of communication sessions between devices e.g. in a Personal Area Network (PAN), or to securely and seamlessly insert any number of service proxies in between session endpoints e.g. to adapt data to suit different devices in a PAN. Identities are securely delegated by relaying HIP signalling messages to the device that owns the private key. This avoids security issues caused by dissemination of private keys. This also ensures that delegated endpoint identities are instantly and permanently revocable by the original device which remains in full control of the private key used to authorize use of the identity. We show that the delegation process introduces minimal additional signalling, and present results of evaluation of a prototype which show the scheme results in no detriment to the performance of HIP.
移动安全主机身份委托
提出了一种基于主机身份协议(HIP)的主机身份授权方案。我们展示了如何应用该方案来实现设备之间通信会话的移动,例如在个人局域网(PAN)中,或者在会话端点之间安全无缝地插入任意数量的服务代理,例如在PAN中调整数据以适应不同的设备。通过将HIP信令消息中继到拥有私钥的设备,身份被安全地委托。这避免了私钥传播带来的安全问题。这还确保了被委托的端点标识可以被原始设备立即永久地撤销,原始设备仍然完全控制用于授权使用标识的私钥。我们证明了授权过程引入了最小的额外信号,并给出了一个原型的评估结果,表明该方案不会损害HIP的性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信