File Download

  • Find it @ UNIST can give you direct access to the published full text of this article. (UNISTARs only)
Related Researcher

Views & Downloads

Detailed Information

Cited time in webofscience Cited time in scopus
Metadata Downloads

An SGX-Based Key Management Framework for Data Centric Networking

Author(s)
Park, MinkyungKim, JeongnyeoKim, YounghoCho, EunsangPark, SoobinSohn, SungminKang, MinhyeokKwon, Ted Taekyoung
Issued Date
2020-03
DOI
10.1109/ACCESS.2020.2978346
URI
https://scholarworks.unist.ac.kr/handle/201301/91138
Fulltext
https://ieeexplore.ieee.org/abstract/document/9024053
Citation
IEEE ACCESS, v.8, pp.45198 - 45210
Abstract
As the Internet has evolved from host-to-host communications to content distribution, data-centric networking is poised to improve networking efficiency. Especially, as the cloud computing, the Internet of Things (IoT), the fifth-generation (5G) networking become popular, there is a consensus that data is to be distributed over some potentially untrusted middleboxes (e.g., CDN servers, web caches) that mediates between data writers and data readers. While data-centric networking designs such as Edge Caching, Global Data Plane (GDP), Named Data Networking (NDN) have been active explored, there have been few studies on how to distribute and manage keys for data access control in such designs with untrusted servers (i.e., middleboxes). We present a key management framework in which symmetric and asymmetric keys are securely managed. A writer publishes his (encrypted) data along with the decryption key for the data. Likewise, an authorized reader retrieves the decryption key as well as the data of interest. To make the key distribution securely between a writer and a reader via an untrusted server, we introduce a key server running on top of the Intel SGX technology. In this way, we can manage and distribute keys for data access control in an efficient and flexible manner. We evaluate the proposed framework by prototyping, which shows some delays in key publishing and retrieval. However, the delays in real operations will be marginal as the period will become longer.
Publisher
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
ISSN
2169-3536
Keyword (Author)
ServersAccess controlDistributed databasesPublic keyInternet of ThingsData-centric networkingkey managementIntel software guard extensiontransport layer security

qrcode

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.