Authorization currently introduces partial centralization in otherwise distributed network architectures, such as ICN approaches. Analyzing existing work in (partially) distributed authentication and authorization, and rearranging proven methods, this paper introduces a generalized, capability based and fully distributed authorization scheme. It argues that such a scheme can fit neatly into ICN architectures in order to enhance the trust model and mitigate against certain classes of denial-of-service attacks. Keywords: authorization, distributed systems security, ICN
翻译:授权目前在原本分布式的网络架构(如信息中心网络方法)中引入了部分中心化。通过分析现有(部分)分布式身份验证与授权的工作,并重新整合经过验证的方法,本文提出了一种通用化的、基于能力的、完全分布式授权方案。论证表明,此类方案可以巧妙地融入信息中心网络架构,以增强信任模型并缓解特定类型的拒绝服务攻击。关键词:授权、分布式系统安全、信息中心网络