Project Title: Securing data objects for future Internet



Acknowledgements: We would like to thank for the Mobility grant support (2015-2016) from Swedish Foundation for Strategic Research (SSF). Also, we would like to thank for the collaboration and support from Ericsson Research, Sweden.



Background and Objectives:

ICN focuses on content retrieval from the network regardless of storage location or physical representation of this content. Thus, securing the data content itself is more important than securing the infrastructure or the end-points. Most existing ICN implementations ensure data integrity as well as authentication by signing data at creation. However, confidentiality remains to be a challenge. One interesting problem with confidentiality is how to present and enforce access control policies. Confidentiality is usually addressed by a trusted third party or by the data owner in traditional Internet architecture. Yet in ICN, data is likely replicated and disseminated in the network, making it difficult for the owner to continue to control the access to the data. A key requirement in ICN is that when the same object is made available to groups with different access credentials this should not result in multiple encrypted objects that needs to be duplicated in the caches.


In this project, we have identified and studied the following research questions.

- How appropriate the functional encryption schemes such as Attribute- or Identity-based encryption for providing data object security in ICNs?

- How to handle revocation of access rights in ICNs?

- What is the key management overhead of encryption-based access control schemes? How would it compare to current mechanisms from usability, performance and security perspectives?

- How to handle access control for dynamic or individualized content?

- Can access-control schemes help with erasing content in ICNs by revoking access to it?








Contact Persons:

Edith Ngai, Uppsala University

Börje Ohlman, Ericsson Research