2002 DARPA Active Networks Conference and Exposition (DANCE'02)
A Prototype Framework for Providing Hop-by-Hop Security in an Experimentally Deployed Active Network
San Francisco, CA
May 29-May 30
ISBN: 0-7695-1564-9
Realizing large-scale active networks is heavily contingent upon addressing security concerns at the outset. Various approaches have been taken toward integrating security within an active node, each defining the mechanisms required to be in place within the Node OS or the Execution Environment in order to provide security guarantees within the system. An acceptable short-term solution to security while deploying an active network in practical testbeds such as the Abone [1] is to divide security concerns into two classes - hop-by-hop and end-to-end. This paper describes an architecture for setting up hop-by-hop packet authentication and integrity using non-active, "off-the-shelf" security components. The intent is for the framework to be generic enough to serve as an aid in securely deploying any new technology requiring mediated node-node security associations including, but not limited to active networks.
Citation:
Suresh Krishnaswamy, Joseph B. Evans, Gary J. Minden, "A Prototype Framework for Providing Hop-by-Hop Security in an Experimentally Deployed Active Network," dance, pp.216, 2002 DARPA Active Networks Conference and Exposition (DANCE'02), 2002