Certificate Distribution with Local Autonomy

  • Authors:
  • Pankaj Kakkar;Michael McDougall;Carl A. Gunter;Trevor Jim

  • Affiliations:
  • -;-;-;-

  • Venue:
  • IWAN '00 Proceedings of the Second International Working Conference on Active Networks
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

Any security architecture for a wide area network system spanning multiple administrative domains will require support for policy delegation and certificate distribution across the network. Practical solutions will support local autonomy requirements of participating domains by allowing local policies to vary but imposing restrictions to ensure overall coherence of the system. This paper describes the design of a such a system to control access to experiments on the ABone active network testbed. This is done through a special-purpose language extending the Query Certificate Manager (QCM) system to include protocols for secure mirroring. Our approach allows significant local autonomy while ensuring global security of the system by integrating verification with retrieval. This enables transparent support for a variety of certificate distribution protocols. We analyze requirements of the ABONE application, describe the design of a security infrastructure for it, and discuss steps toward implementation, testing and deployment of the system.