发布/订阅作为分布式系统中一种松耦合、多对多的异步通信机制,有着广泛的应用前景。目前,人们主要对匹配算法、路由算法的性能、可表达性进行了深入的研究,其安全方面研究不足。因此,分析了发布/订阅系统的安全需求,设计了发布/订阅系统安全框架,并结合SRP协议,对框架中的身份认证机制、密钥管理机制、以及订阅成员的动态管理机制进行了详细的设计与分析,论证了该框架能满足发布/订阅系统的基本安全需求,具有实际应用价值。
Publish-subscribe system, as a loosely-coupled, many-to-many asynchronous communication mechanism in distributed sys- tems, will be widely used in various areas. At present, some aspects of such systems have been the focus of intensive research, such as expression, performance of matching algorithms and routing algorithms. Little attention has been given to security issues. The security requirement of publish-Subscribe system based on content is analyzed, and then the security framework is designed. Some aspects of it, such as identity authentication, key management mechanism and dynamic subscriber membership management mechanism, are discussed and analyzed by combination with SRP protocol. Analyses show that the security framework meet the basic security requirement of current Publish-Subscribe system.