REMOTEGATE: Incentive-Compatible Remote Configuration of Security Gateways
Abhinav Aggarwal, Mahdi Zamani, Mihai Christodorescu

TL;DR
This paper presents REMOTEGATE, an incentive-compatible protocol enabling servers to securely and reliably configure untrusted security gateways to block attack packets, using digital payments to motivate correct behavior.
Contribution
It introduces a novel interactive mechanism that ensures trustworthy remote configuration of security gateways through incentive alignment and verification.
Findings
Protocol guarantees correct rule deployment before payment
Enables scalable, incentive-driven security improvements
Supports secure, remote gateway configuration at Internet scale
Abstract
Imagine that a malicious hacker is trying to attack a server over the Internet and the server wants to block the attack packets as close to their point of origin as possible. However, the security gateway ahead of the source of attack is untrusted. How can the server block the attack packets through this gateway? In this paper, we introduce REMOTEGATE, a trustworthy mechanism for allowing any party (server) on the Internet to configure a security gateway owned by a second party, at a certain agreed upon reward that the former pays to the latter for its service. We take an interactive incentive-compatible approach, for the case when both the server and the gateway are rational, to devise a protocol that will allow the server to help the security gateway generate and deploy a policy rule that filters the attack packets before they reach the server. The server will reward the gateway only…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Access Control and Trust · Distributed systems and fault tolerance
