互联网统一征服架构

Kamyab Karimi, C. Hauser
{"title":"互联网统一征服架构","authors":"Kamyab Karimi, C. Hauser","doi":"10.1109/ICITST.2013.6750195","DOIUrl":null,"url":null,"abstract":"This paper presents UnC (Unite and Conquer), a network architecture for the Internet that provides a self-certifying mechanism to reliably distribute, retrieve, and authenticate the public keys across the Internet. UnC may be used in parallel with the existing Public Key Infrastructure (PKI) ecosystem to provide an additional validation step for certificates offered by the PKI model. Leveraging the properties of the Internet infrastructure combined with cooperation from other hosts that act as notaries, UnC attests to the stability of certificates in time and space. By uniting notaries, UnC overwhelms and outnumbers attackers, and it uses this unity to conquer attack plots. Unlike existing proposals aimed to incorporate accountability into the Internet, UnC does not require external certificate hierarchies or certificate authorities to manage digital certificates. UnC can also be integrated in the Secure DNS (DNSSEC) protocols as well as the Secure BGP (S-BGP) protocol to eliminate the need for external key structures while protecting bindings between the entities and their IP addresses, and the integrity of the routing tables between Autonomous Systems. This paper describes the UnC architecture in detail, including the actions of each different kind of participant. It describes how UnC deals with well-known attack models, which are readily available on the Internet.The major contribution of this work is to open up a new door for the research community to exploit the predominance of good nodes over malicious ones in order to enhance the security of the PKI ecosystem and the Internet.","PeriodicalId":246884,"journal":{"name":"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Internet Unite-and-Conquer architecture\",\"authors\":\"Kamyab Karimi, C. Hauser\",\"doi\":\"10.1109/ICITST.2013.6750195\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper presents UnC (Unite and Conquer), a network architecture for the Internet that provides a self-certifying mechanism to reliably distribute, retrieve, and authenticate the public keys across the Internet. UnC may be used in parallel with the existing Public Key Infrastructure (PKI) ecosystem to provide an additional validation step for certificates offered by the PKI model. Leveraging the properties of the Internet infrastructure combined with cooperation from other hosts that act as notaries, UnC attests to the stability of certificates in time and space. By uniting notaries, UnC overwhelms and outnumbers attackers, and it uses this unity to conquer attack plots. Unlike existing proposals aimed to incorporate accountability into the Internet, UnC does not require external certificate hierarchies or certificate authorities to manage digital certificates. UnC can also be integrated in the Secure DNS (DNSSEC) protocols as well as the Secure BGP (S-BGP) protocol to eliminate the need for external key structures while protecting bindings between the entities and their IP addresses, and the integrity of the routing tables between Autonomous Systems. This paper describes the UnC architecture in detail, including the actions of each different kind of participant. It describes how UnC deals with well-known attack models, which are readily available on the Internet.The major contribution of this work is to open up a new door for the research community to exploit the predominance of good nodes over malicious ones in order to enhance the security of the PKI ecosystem and the Internet.\",\"PeriodicalId\":246884,\"journal\":{\"name\":\"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)\",\"volume\":\"5 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICITST.2013.6750195\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITST.2013.6750195","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

本文介绍了UnC(联合与征服),这是一种互联网网络体系结构,它提供了一种自认证机制,可以在互联网上可靠地分发、检索和验证公钥。UnC可以与现有的公钥基础设施(PKI)生态系统并行使用,为PKI模型提供的证书提供额外的验证步骤。UnC利用互联网基础设施的特性,结合其他充当公证人的主机的合作,证明了证书在时间和空间上的稳定性。通过联合公证人,UnC压倒攻击者,并利用这种团结来征服攻击阴谋。与现有旨在将问责制纳入互联网的提案不同,UnC不需要外部证书层次结构或证书颁发机构来管理数字证书。UnC也可以集成在DNSSEC (Secure DNS)协议和S-BGP (Secure BGP)协议中,在保护实体和IP地址之间的绑定和自治系统之间路由表的完整性的同时,消除对外部密钥结构的需求。本文详细描述了UnC体系结构,包括每种不同类型参与者的动作。它描述了UnC如何处理众所周知的攻击模型,这些模型在互联网上随处可见。这项工作的主要贡献是为研究社区打开了一扇新的大门,利用好节点对恶意节点的优势,以增强PKI生态系统和互联网的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Internet Unite-and-Conquer architecture
This paper presents UnC (Unite and Conquer), a network architecture for the Internet that provides a self-certifying mechanism to reliably distribute, retrieve, and authenticate the public keys across the Internet. UnC may be used in parallel with the existing Public Key Infrastructure (PKI) ecosystem to provide an additional validation step for certificates offered by the PKI model. Leveraging the properties of the Internet infrastructure combined with cooperation from other hosts that act as notaries, UnC attests to the stability of certificates in time and space. By uniting notaries, UnC overwhelms and outnumbers attackers, and it uses this unity to conquer attack plots. Unlike existing proposals aimed to incorporate accountability into the Internet, UnC does not require external certificate hierarchies or certificate authorities to manage digital certificates. UnC can also be integrated in the Secure DNS (DNSSEC) protocols as well as the Secure BGP (S-BGP) protocol to eliminate the need for external key structures while protecting bindings between the entities and their IP addresses, and the integrity of the routing tables between Autonomous Systems. This paper describes the UnC architecture in detail, including the actions of each different kind of participant. It describes how UnC deals with well-known attack models, which are readily available on the Internet.The major contribution of this work is to open up a new door for the research community to exploit the predominance of good nodes over malicious ones in order to enhance the security of the PKI ecosystem and the Internet.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信