Back to Search
Start Over
Secure receiver access control for IP multicast at the network level: Design and validation
- Source :
- Computer Networks. 102:109-128
- Publication Year :
- 2016
- Publisher :
- Elsevier BV, 2016.
-
Abstract
- The classical service model of IP multicast is open; anyone can receive multicast data. When using this model, it is impossible to ensure that receivers are authorized to receive the data, or (if appropriate) to generate any revenue from a service based on open multicast. This has resulted in restricted deployment of IP multicast.We have developed a secure IP multicast architecture to enforce receiver access control at two levels: application level and network level. This paper addresses the design and validation of the solution at the network level. The design starts from four assumptions, which express the independence of the network-level solution from the previous work at the application level. At the network level, receiver access control is achieved using two proposed protocols: Secure Internet Group Management Protocol (SIGMP) and Group Security Association Management (GSAM) protocol.SIGMP is an extension to IGMP, in which the messages that are related to secure groups are protected by IPsec Group Security Associations (GSAs). GSAM manages the IPsec GSAs used in SIGMP and couples the network-level access control with the application-level access control.The design requirements for SIGMP and for GSAM are expressed in terms of Design Criteria and Security Goals. These design requirements are then used to justify the final design. Several security properties of GSAM have been formally validated using AVISPA and the remaining security properties of our proposal have been analyzed.
- Subjects :
- Multicast
Computer Networks and Communications
business.industry
computer.internet_protocol
Computer science
020206 networking & telecommunications
Access control
02 engineering and technology
Computer security
computer.software_genre
Source-specific multicast
Security association
Internet Group Management Protocol
IPsec
0202 electrical engineering, electronic engineering, information engineering
IP multicast
020201 artificial intelligence & image processing
Xcast
business
computer
Computer network
Subjects
Details
- ISSN :
- 13891286
- Volume :
- 102
- Database :
- OpenAIRE
- Journal :
- Computer Networks
- Accession number :
- edsair.doi...........62e43748bf410f152671305278c26fc4