The Architecture and Performance of Security Protocols in the Ensemble Group Communication System - Using Diamonds to Guard the Castle

Ohad Rodeh, Ken Birman, Danny Dolev · 2000

Ensemble is a Group Communication System built at Cornell and the Hebrew universities. It allows processes to create process groups within which scalable reliable fo-ordered multicast and point-to-point communication are supported. The system also supports other communication properties, such as causal and total multicast ordering, ow control, etc. This paper describes the security protocols and infrastructure of Ensemble. Applications using Ensemble with the extensions described here benet from strong security properties. Under the assumption that trusted processes will not be corrupted, all communication is secured from tampering by outsiders. Our work extends previous work performed in the Horus system (Ensemble's predecessor) by adding support for multiple partitions, ecient rekeying, and application dened security policies. Unlike Horus, which used its own security infrastructure with non-standard key distribution and timing services, Ensemble's security mechanism i...

Read the paper · More papers on PaperTik