Suppr超能文献

基于发布/订阅中间件实现物联网服务的策略隐私。

Realizing IoT service's policy privacy over publish/subscribe-based middleware.

作者信息

Duan Li, Zhang Yang, Chen Shiping, Wang Shiyao, Cheng Bo, Chen Junliang

机构信息

State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, 100876 China ; Data61, CSIRO, Marsfield, NSW 2122 Australia.

State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, 100876 China.

出版信息

Springerplus. 2016 Sep 20;5(1):1615. doi: 10.1186/s40064-016-3250-x. eCollection 2016.

Abstract

The publish/subscribe paradigm makes IoT service collaborations more scalable and flexible, due to the space, time and control decoupling of event producers and consumers. Thus, the paradigm can be used to establish large-scale IoT service communication infrastructures such as Supervisory Control and Data Acquisition systems. However, preserving IoT service's policy privacy is difficult in this paradigm, because a classical publisher has little control of its own event after being published; and a subscriber has to accept all the events from the subscribed event type with no choice. Few existing publish/subscribe middleware have built-in mechanisms to address the above issues. In this paper, we present a novel access control framework, which is capable of preserving IoT service's policy privacy. In particular, we adopt the publish/subscribe paradigm as the IoT service communication infrastructure to facilitate the protection of IoT services policy privacy. The key idea in our policy-privacy solution is using a two-layer cooperating method to match bi-directional privacy control requirements: (a) data layer for protecting IoT events; and (b) application layer for preserving the privacy of service policy. Furthermore, the anonymous-set-based principle is adopted to realize the functionalities of the framework, including policy embedding and policy encoding as well as policy matching. Our security analysis shows that the policy privacy framework is Chosen-Plaintext Attack secure. We extend the open source Apache ActiveMQ broker by building into a policy-based authorization mechanism to enforce the privacy policy. The performance evaluation results indicate that our approach is scalable with reasonable overheads.

摘要

发布/订阅范式使物联网服务协作更具可扩展性和灵活性,这得益于事件生产者和消费者在空间、时间及控制方面的解耦。因此,该范式可用于建立大规模的物联网服务通信基础设施,如监控与数据采集系统。然而,在这种范式下保护物联网服务的策略隐私很困难,因为传统发布者在发布自身事件后对其几乎没有控制权;而订阅者必须毫无选择地接受来自所订阅事件类型的所有事件。现有的发布/订阅中间件很少有内置机制来解决上述问题。在本文中,我们提出了一种新颖的访问控制框架,它能够保护物联网服务的策略隐私。具体而言,我们采用发布/订阅范式作为物联网服务通信基础设施,以促进对物联网服务策略隐私的保护。我们的策略隐私解决方案的关键思想是使用一种两层协作方法来匹配双向隐私控制要求:(a)数据层用于保护物联网事件;(b)应用层用于保护服务策略的隐私。此外,采用基于匿名集的原则来实现框架的功能,包括策略嵌入、策略编码以及策略匹配。我们的安全分析表明,该策略隐私框架在选择明文攻击下是安全的。我们通过在开源的Apache ActiveMQ代理中构建基于策略的授权机制来实施隐私策略,对其进行了扩展。性能评估结果表明,我们的方法具有可扩展性且开销合理。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ebc1/5028380/9afdb15c59c6/40064_2016_3250_Fig1_HTML.jpg

相似文献

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验