Secure mediation: requirements, design, and architecture

  • Authors:
  • C. Altenschmidt;J. Biskup;U. Flegel;Y. Karabulut

  • Affiliations:
  • Universität Dortmund, Informatik VI, D-44221 Dortmund, Germany;Universität Dortmund, Informatik VI, D-44221 Dortmund, Germany;Universität Dortmund, Informatik VI, D-44221 Dortmund, Germany;Universität Dortmund, Informatik VI, D-44221 Dortmund, Germany

  • Venue:
  • Journal of Computer Security - IFIP 2000
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

In mediated information systems clients and various autonomous sources are brought together by mediators. The mediation paradigm needs powerful and expressive security mechanisms considering the dynamics and conflicting interests of the mediation participants. Firstly, we discuss the security requirements for mediation with an emphasis on confidentiality and authenticity. We argue for basing the enforcement of these properties on certified personal authorization attributes rather than on identification. Using a public key infrastructure such personal authorization attributes can be bound to asymmetric encryption keys by credentials. Secondly, we propose a general design of secure mediation where credentials are roughly used as follows: clients show their eligibility for receiving requested information by the contained personal authorization attributes, and sources and the mediator guarantee confidentiality by using the contained encryption keys. Thirdly, we refine the general design for a specific approach to mediation, given by our prototype of a Multimedia Mediator, MMM. Among other contributions, we define the authorization model and the specification of query access authorizations within the framework of ODL, as well as the authorization and encryption policies for mediation, and we outline the resulting security architecture of the MMM. We also analyze the achievable security properties including support for anonymity, and we discuss the inevitable tradeoffs between security and mediation functionality.