Security properties in an open peer-to-peer network
Jean-Francois Lalande, David Rodriguez, Christian Toinard (Ensi de, Bourges, France)

TL;DR
This paper introduces a novel architecture for open peer-to-peer networks that enforces security properties like confidentiality, integrity, and availability, by evaluating trust and automatically configuring security policies.
Contribution
It proposes an architecture that formalizes security requirements, assesses peer trustworthiness, and automatically enforces security policies via SELinux in peer-to-peer networks.
Findings
Formal security property definition for shared resources
Trust and reputation evaluation through challenge-response
Automatic SELinux policy configuration for security enforcement
Abstract
This paper proposes to address new requirements of confidentiality, integrity and availability properties fitting to peer-to-peer domains of resources. The enforcement of security properties in an open peer-topeer network remains an open problem as the literature have mainly proposed contribution on availability of resources and anonymity of users. That paper proposes a novel architecture that eases the administration of a peer-to-peer network. It considers a network of safe peer-to-peer clients in the sense that it is a commune client software that is shared by all the participants to cope with the sharing of various resources associated with different security requirements. However, our proposal deals with possible malicious peers that attempt to compromise the requested security properties. Despite the safety of an open peer-to-peer network cannot be formally guaranteed, since a end…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPeer-to-Peer Network Technologies · Access Control and Trust · Caching and Content Delivery
