FIDO-Based Access Control Mechanism in Named Data Networking
摘要
In contrast to the conventional IP-based architecture, Named Data Networking (NDN) provides a content-centric, secure, efficient, and scalable network approach, making it suitable for various applications such as content delivery and data dissemination. However, in NDN, the information carried in the Interest packets includes only essential data names, which enhances privacy and security but complicates the identification of the client requester. This study introduces an access control mechanism incorporating FIDO U2F devices for user authentication and replacing the original client names with IDs to enhance privacy protection. The proposed framework empowers the Access Controller to verify the source of Interest packets, thereby determining whether the client has the authorization to access the data. We compare and analyze the authentication mechanisms of the proposed architecture with other access control architectures. Our findings show that the proposed architecture has more flexible permission settings and can effectively protect clients’ identity privacy.