Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -8,19 +8,19 @@
|
||||
|
||||
> **Characteristics**
|
||||
>
|
||||
> * High intermittent connectivity
|
||||
> * Extremely long message travel time
|
||||
> * Delay: finite speed of light
|
||||
> * Low Transmission reliability
|
||||
> * Inaccurate position
|
||||
> * Limited visibility
|
||||
> * Low asymmetric Data Rate
|
||||
> - High intermittent connectivity
|
||||
> - Extremely long message travel time
|
||||
> - Delay: finite speed of light
|
||||
> - Low Transmission reliability
|
||||
> - Inaccurate position
|
||||
> - Limited visibility
|
||||
> - Low asymmetric Data Rate
|
||||
>
|
||||
> **Security**
|
||||
>
|
||||
> - CCSDS protocol
|
||||
> - space End to End security
|
||||
> - space end to end reliability
|
||||
> - space End to End security
|
||||
> - space end to end reliability
|
||||
|
||||
##### Military
|
||||
|
||||
@@ -28,12 +28,12 @@
|
||||
>
|
||||
> **Characteristics**
|
||||
>
|
||||
> * High intermittent connectivity
|
||||
> * Mobility, destruction, noise & attacks, interference
|
||||
> * Low transmission reliability
|
||||
> * positioning inaccuracy
|
||||
> * limited visibility
|
||||
> * Low data rate
|
||||
> - High intermittent connectivity
|
||||
> - Mobility, destruction, noise & attacks, interference
|
||||
> - Low transmission reliability
|
||||
> - positioning inaccuracy
|
||||
> - limited visibility
|
||||
> - Low data rate
|
||||
>
|
||||
> **Security**
|
||||
>
|
||||
@@ -43,89 +43,89 @@
|
||||
|
||||
##### Rural Areas
|
||||
|
||||
>Providing internet connectivity to rural/developing areas
|
||||
> Providing internet connectivity to rural/developing areas
|
||||
>
|
||||
>**Characteristics**
|
||||
> **Characteristics**
|
||||
>
|
||||
>- Intermittent connectivity
|
||||
>- Mobility - sparse development
|
||||
>- High propagation delay
|
||||
>- Asymmetric data rate
|
||||
> - Intermittent connectivity
|
||||
> - Mobility - sparse development
|
||||
> - High propagation delay
|
||||
> - Asymmetric data rate
|
||||
>
|
||||
>
|
||||
> 
|
||||
>
|
||||
>**Security**
|
||||
> **Security**
|
||||
>
|
||||
>- Standard cryptographic techniques such as PKI and transparent encrypted file systems
|
||||
> - Standard cryptographic techniques such as PKI and transparent encrypted file systems
|
||||
|
||||
- Disaster struck areas
|
||||
- Disaster-struck areas
|
||||
- Disconnected kiosks in rural areas
|
||||
- Remote sensing applications
|
||||
|
||||
But also
|
||||
|
||||
- Bulk data distribution in urban areas
|
||||
- Sharing of individual contents in urban areas
|
||||
- Mobile location-aware sensing application
|
||||
- Sharing of individual content in urban areas
|
||||
- Mobile location-aware sensing applications
|
||||
- Social mobile applications
|
||||
|
||||
#### DTN Security Goals
|
||||
|
||||
Due to the resource-causticity that DTNs have, the focus is on protecting the DTN infrastructure from unauthorised access and use.
|
||||
Due to the resource scarcity of DTNs, the focus is on protecting the DTN infrastructure from unauthorised access and use.
|
||||
|
||||
* Prevent **access** by unauthorised applications.
|
||||
* Prevent unauthorised applications from asserting control over DTN infrastructure.
|
||||
* Prevent authorised applications from sending bundles at a rate or class of service for which they **don't have permissions for**.
|
||||
* Detect and discard bundles that were sent from unauthorised applications/users.
|
||||
* Detect and discard bundles who's headers have been modified.
|
||||
* Detect and discard compromised entities.
|
||||
- Prevent **access** by unauthorised applications.
|
||||
- Prevent unauthorised applications from asserting control over DTN infrastructure.
|
||||
- Prevent authorised applications from sending bundles at a rate or class of service for which they **don't have permission**.
|
||||
- Detect and discard bundles that were sent from unauthorised applications/users.
|
||||
- Detect and discard bundles whose headers have been modified.
|
||||
- Detect and discard compromised entities.
|
||||
|
||||
Secondary emphasis is on providing optional end-to-end security services to bundle applications.
|
||||
|
||||
#### DTN Security Challenges
|
||||
|
||||
* High round-trip times and disconnections
|
||||
* Do not allow frequent distribution of a large number of certificates and encryption keys end-to-end.
|
||||
* More scalable to use user's keys and credentials at neighbouring or nearby nodes.
|
||||
* Delays or loss of connectivity to a key or certificate server
|
||||
* Multiple certificate authorities desirable but not sufficient and certificate revocation not appropriate
|
||||
* Long delays
|
||||
* Messages may be valid for days/weeks, so message expiration may not be able to be depended on to rid the network of unwanted messages as efficiently as in other types of networks.
|
||||
* Constrained Bandwidth
|
||||
* Need to minimise the cost of security in terms of network overhead (header bits).
|
||||
- High round-trip times and disconnections
|
||||
- Do not allow frequent distribution of a large number of certificates and encryption keys end-to-end.
|
||||
- More scalable to use users' keys and credentials at neighbouring or nearby nodes.
|
||||
- Delays or loss of connectivity to a key or certificate server
|
||||
- Multiple certificate authorities desirable but not sufficient and certificate revocation not appropriate
|
||||
- Long delays
|
||||
- Messages may be valid for days/weeks, so message expiration may not be able to be depended on to rid the network of unwanted messages as efficiently as in other types of networks.
|
||||
- Constrained Bandwidth
|
||||
- Need to minimise the cost of security in terms of network overhead (header bits).
|
||||
|
||||
###### Traditional PKI not applicable
|
||||
|
||||
* Traditional symmetric cryptography approaches are not suitable for DTNs for two major reasons
|
||||
* In PKI a user authenticates another users public key using a certificate
|
||||
* This is not possible without online access to the receivers public key or certificates
|
||||
* PKIs implement key revocation based on frequently updated online certificate revocation lists
|
||||
* In the absence of instant online access to CAs servers, a receiver cannot authenticate the sender's certificate.
|
||||
- Traditional symmetric cryptography approaches are not suitable for DTNs for two major reasons
|
||||
- In PKI, a user authenticates another user's public key using a certificate
|
||||
- This is not possible without online access to the receiver's public key or certificates
|
||||
- PKIs implement key revocation based on frequently updated online certificate revocation lists
|
||||
- In the absence of instant online access to CAs' servers, a receiver cannot authenticate the sender's certificate.
|
||||
|
||||
###### Identity Based Cryptography not applicable
|
||||
|
||||
Identity Based Cryptography (IBC) schemes where the public key of each entity is replaced by its identity and associated public formatting policies are not suitable for the security in DTNs
|
||||
Identity-Based Cryptography (IBC) schemes, where the public key of each entity is replaced by its identity and associated public formatting policies, are not suitable for security in DTNs.
|
||||
|
||||
- IBC does not solve the key management problem in DTNs
|
||||
- It is not scalable because it assumes that a user must know the public parameters for all the trusted parties.
|
||||
|
||||
###### Mobile ad hoc Key Management Proposals not applicable
|
||||
|
||||
- Virtual Certificate Authority
|
||||
- Not applicable due to no trusted third parties
|
||||
- Virtual Certificate Authority
|
||||
- Not applicable due to the absence of trusted third parties
|
||||
- Certificate chaining based on pretty good privacy (PGP)
|
||||
- Not applicable due to insufficient density of certificate graphs
|
||||
- Peer-to-peer key management based on mobilty
|
||||
- Not applicable due to certificate revocation mechanism
|
||||
- Not applicable due to insufficient density of certificate graphs
|
||||
- Peer-to-peer key management based on mobility
|
||||
- Not applicable due to certificate revocation mechanism
|
||||
|
||||
#### Existing Mandatory DTN Security
|
||||
|
||||
Based on the *bundle* protocol
|
||||
|
||||
* Hop-by-hop bundle integrity
|
||||
* Hop-by-hop bundle sender authentication
|
||||
* Access Control (only legit users with right permissions)
|
||||
* Limited protection from DoS attacks
|
||||
- Hop-by-hop bundle integrity
|
||||
- Hop-by-hop bundle sender authentication
|
||||
- Access Control (only legit users with right permissions)
|
||||
- Limited protection from DoS attacks
|
||||
|
||||

|
||||
|
||||
|
||||
Reference in new issue
Block a user