节点文献

基于属性的DDS访问控制机制研究

Research on Attribute Based Access Control Mechanisms for DDS

【作者】 陈莹;

【导师】 沈卓炜; 张琳;

【作者基本信息】 东南大学 , 电子信息(专业学位), 2023, 硕士

【摘要】 数据分发服务(Data Distribution Service,DDS)是以数据为中心的分布式实时通信中间件标准,具备松耦合、高效可靠、可扩展等特性,可实现高效、安全及可靠的数据分发。随着发布/订阅通信模式的普及,DDS也面临着许多安全威胁,例如未授权的发布、未授权的订阅、数据窃听和篡改等,因此,迫切需要建立灵活可靠的安全机制来保证发布/订阅通信模式下数据共享的安全性。为解决DDS面临的安全威胁,DDS安全规范以安全服务插件的形式在DDS中增加安全机制,在参与者发现匹配和数据分发过程中添加身份认证、访问控制、数据加解密等安全措施,保障了数据的机密性和完整性。DDS安全规范中数据加密采用对称加密方式,加密方与解密方具有确定的对应关系,与DDS通信系统中发布者、订阅者解耦的模式不相适应。DDS参与者借助访问控制列表进行访问控制,无法制定复杂的访问控制策略,并且无法满足参与者属性动态变化的需求。针对上述问题,论文结合KP-ABE加密技术和ABAC访问控制模型,提出了一种基于属性的DDS访问控制机制。在保障数据机密传输的基础上,实现了基于属性的DDS细粒度访问控制,并且支持DDS参与者属性的动态变化。论文的主要工作包括:(1)提出了基于KP-ABE和ABAC的DDS安全访问控制方案(Key Policy Attribute Based Access Control Model for DDS,即KPABAC-DDS)。在DDS系统准备阶段,由DDS策略管理者统一制定访问控制策略,并通过属性权威中心签发属性证书,保障参与者属性的有效性。当参与者的属性发生变化时,属性权威中心会对其属性证书进行动态更新;在DDS发现匹配阶段,DDS通信系统利用自动发现机制来控制DDS参与者之间的发布/订阅关系的建立;在DDS发布订阅阶段,通过ABAC访问判决的结果来控制订阅者获取解密密钥,只有通过访问判决的订阅者才能获得解密密钥。同时,在KP-ABE算法中引入属性名值对的概念,实现了ABAC模型与KP-ABE算法之间的共享属性库。(2)针对KPABAC-DDS方案仅支持离散的属性表达的问题,提出了支持属性谓词的访问控制改进方案。设计属性映射算法,将<属性名,属性值>形式的属性名值对转化为支持连续的属性表达的<属性名,运算符,属性值>形式的属性谓词,利用属性谓词对发布数据进行加密。DDS策略管理者直接使用ABAC访问控制策略生成用户解密密钥,实现ABAC模型与KP-ABE算法共享策略库。经过改进,论文的方案可有效处理数据属性和访问策略的动态变化,从而实现更加灵活的访问控制。(3)基于国产自主可控的u DDS中间件系统,集成论文提出的上述机制,设计并实现了基于属性的DDS访问控制原型系统,并对原型系统进行了功能测试和性能测试。测试结果表明,与其他DDS访问控制方案相比,论文提出的方案能够实现基于属性的DDS细粒度访问控制,并且支持参与者属性的动态变化。此外,在实现系统安全目标的同时,还保证了DDS的实时处理性能,不仅对DDS发布/订阅时延的影响较小,吞吐量也优于其他方案。

【Abstract】 The DDS(Data Distribution Service)is a standard for data-centric distributed real-time communication middleware that is loosely coupled,efficient,reliable and scalable,and it enables efficient,secure and reliable data distribution.With the popularity of the publish/subscribe communication model,DDS is also exposed to many security threats such as unauthorized publication/subscription,data eavesdropping and tampering.It is urgent to establish flexible and reliable security mechanisms to ensure the security of data sharing in the publish/subscribe communication model.To address the above threats,the DDS Security Specification adds security mechanisms to DDS in the form of a security service plug-in.Security measures such as authentication,access control and data encryption and decryption are added to the participant discovery matching and data distribution process to safeguard the confidentiality and integrity of the data.The DDS security specification uses symmetric encryption for data encryption,where the encrypting party has a definite correspondence with the decrypting party,contradicting the model of decoupling publisher and subscriber in DDS communication systems.DDS participants rely on access control lists for access control,which do not allow for complex access control policies and do not meet the needs of dynamic changes in participant attributes.To address the above issues,the thesis proposes an attribute-based DDS access control mechanism by combining KP-ABE and ABAC.Attribute based fine-grained access control for DDS is implemented on the basis of safeguarding confidential data transmission and supporting dynamic changes in the attributes of DDS participants.The main work of the thesis includes:(1)A Key Policy Attribute Based Access Control Model for DDS(KPABAC-DDS)based on KP-ABE and ABAC is proposed.In the preparation stage of the DDS system,the DDS policy administrator unifies the access control policy and issues attribute certificates through the attribute authority center to guarantee the validity of the participants’ attributes.When a participant’s attributes change,the attribute authority center dynamically updates its attribute certificate.In the DDS discovery matching phase,the DDS communication system uses an automatic discovery mechanism to control the establishment of publish/subscribe relationships between DDS participants.In the DDS publish/subscribe phase,the result of ABAC access verdict is used to control the subscribers to obtain the decryption key,and only the subscribers who pass the access verdict can obtain the decryption key.Meanwhile,the concept of attribute name-value pairs is introduced into the KP-ABE algorithm to achieve a shared attribute library between the ABAC model and the KP-ABE algorithm.(2)In response to the problem that the KPABAC-DDS scheme only supports discrete attribute expressions,an improved access control scheme that supports attribute predicates is proposed.The attribute mapping algorithm is designed to transform attribute name-value pairs in the form of <attribute name,attribute value> into attribute predicates in the form of <attribute name,operator,attribute value> that support continuous attribute expression,and encrypt the published data using the attribute predicates.The DDS policy manager directly uses the ABAC access control policy to generate user decryption keys,and implements the ABAC model with the KP-ABE algorithm to share policy libraries.The improved scheme of the thesis is able to effectively handle dynamic changes in data attributes and access policies,thus enabling more flexible access control.(3)Based on the u DDS middleware system,the above mechanism proposed in the thesis is integrated to design and implement a prototype system for attribute-based DDS access control,and the prototype system was tested for functionality and performance.The results show that the scheme proposed in the thesis enables attribute-based fine-grained access control of DDS and supports dynamic changes in participant attributes compared to other DDS access control schemes.In addition,it achieves system security objectives while ensuring real-time processing performance of the DDS,not only with less impact on DDS publish/subscribe latency,but also with better throughput than other schemes.

  • 【网络出版投稿人】 东南大学
  • 【网络出版年期】2025年 04期
  • 【分类号】TP311.13;TP309
节点文献中: 

本文链接的文献网络图示:

本文的引文网络