19th Annual Computer Security Applications Conference (ACSAC '03)
Differential Data Protection for Dynamic Distributed Applications
Las Vegas, Nevada
December 08-December 12
ISBN: 0-7692-2041-3
We present a mechanism for providing differential data protection to publish/subscribe distributed systems, such as those used in peer-to-peer computing, grid environments, and others. This mechanism, termed "security overlays", incorporates credential-based communication channel creation, subscription and extension. We describe a conceptual model of publish/subscribe services that is made concrete by our mechanism. We also present an application, Active Video Streams, whose reimplementation using security overlays allows it to react to high-level security policies specified in XML without significant performance loss or the necessity for embedding policy-specific code into the application.
Citation:
Patrick Widener, Karsten Schwan, Fabian E. Bustamante, "Differential Data Protection for Dynamic Distributed Applications," acsac, pp.396, 19th Annual Computer Security Applications Conference (ACSAC '03), 2003