DistriTrust: Distributed and low-latency access validation in zero-trust architecture. (December 2021)
- Record Type:
- Journal Article
- Title:
- DistriTrust: Distributed and low-latency access validation in zero-trust architecture. (December 2021)
- Main Title:
- DistriTrust: Distributed and low-latency access validation in zero-trust architecture
- Authors:
- Sengupta, Binanda
Lakshminarayanan, Anantharaman - Abstract:
- Abstract: Enterprise networks typically use perimeter-based security to protect their IT resources from security threats originating from outside the enterprise perimeter. In such networks, connection requests from devices residing inside the perimeter are implicitly assumed to be trusted. However, in practice, a considerable fraction of cyberattacks emanate from inside the enterprise network making the perimeter-based trust assumption unrealistic. Zero-trust architecture (ZTA) is an emerging alternative to perimeter-based security, where each connection request for accessing an enterprise resource goes through stringent security checks and validation irrespective of the location of the requesting device. In ZTA, every connection request is authenticated and authorized by a trusted centralized component called the policy decision point (PDP) and subsequently granted (or denied) access to the requested resource. However, the centralized nature of the PDP often makes it vulnerable to various attacks such as compromise of secret keys, impersonation and denial of service. In this article, we propose DistriTrust which distributes trust across multiple PDPs using the notion of threshold signatures. However, involving multiple PDPs also increases latency. In order to keep latency as low as possible, we study different threshold signature schemes and identify a suitable scheme for DistriTrust . We also discuss the security properties achieved by DistriTrust . Finally, we analyze theAbstract: Enterprise networks typically use perimeter-based security to protect their IT resources from security threats originating from outside the enterprise perimeter. In such networks, connection requests from devices residing inside the perimeter are implicitly assumed to be trusted. However, in practice, a considerable fraction of cyberattacks emanate from inside the enterprise network making the perimeter-based trust assumption unrealistic. Zero-trust architecture (ZTA) is an emerging alternative to perimeter-based security, where each connection request for accessing an enterprise resource goes through stringent security checks and validation irrespective of the location of the requesting device. In ZTA, every connection request is authenticated and authorized by a trusted centralized component called the policy decision point (PDP) and subsequently granted (or denied) access to the requested resource. However, the centralized nature of the PDP often makes it vulnerable to various attacks such as compromise of secret keys, impersonation and denial of service. In this article, we propose DistriTrust which distributes trust across multiple PDPs using the notion of threshold signatures. However, involving multiple PDPs also increases latency. In order to keep latency as low as possible, we study different threshold signature schemes and identify a suitable scheme for DistriTrust . We also discuss the security properties achieved by DistriTrust . Finally, we analyze the asymptotic performance of DistriTrust and report the experimental results as well. … (more)
- Is Part Of:
- Journal of information security and applications. Volume 63(2022)
- Journal:
- Journal of information security and applications
- Issue:
- Volume 63(2022)
- Issue Display:
- Volume 63, Issue 2022 (2022)
- Year:
- 2022
- Volume:
- 63
- Issue:
- 2022
- Issue Sort Value:
- 2022-0063-2022-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-12
- Subjects:
- Cybersecurity -- Zero-trust architecture -- Access validation -- Threshold signatures -- Low latency
Computer security -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.jisa.2021.103023 ↗
- Languages:
- English
- ISSNs:
- 2214-2126
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 20172.xml