论文标题
关于命名数据网络中的证书管理
On Certificate Management in Named Data Networking
论文作者
论文摘要
命名数据网络(NDN)通过要求生产时签署所有数据包来确保网络通信。这项要求需要有效且可用的机制来处理NDN证书的发行和撤销,从而使这些支持机制对于NDN操作必不可少。在本文中,我们首先调查并阐明与NDN证书和安全设计有关的核心概念,然后介绍NDN证书管理及其所需属性的模型。我们继续设计NDN证书管理的特定实现,NDNCERT,使用正式的安全分析对其进行评估,并讨论设计,实施和部署系统的挑战,以与其他NDN安全协议开发工作分享我们的经验。
Named Data Networking (NDN) secures network communications by requiring all data packets to be signed when produced. This requirement necessitates efficient and usable mechanisms to handle NDN certificate issuance and revocation, making these supporting mechanisms essential for NDN operations. In this paper, we first investigate and clarify core concepts related to NDN certificates and security design in general, and then present the model of NDN certificate management and its desired properties. We proceed with the design of a specific realization of NDN's certificate management, NDNCERT, evaluate it using a formal security analysis, and discuss the challenges in designing, implementing, and deploying the system, to share our experiences with other NDN security protocol development efforts.