Non-repudiable service usage with host identities

Seppo Heikkinen · 2007

Security design of many communication systems relies on the authentication of the users, but equally important is to consider the authorisation of actions. Often authorisation is implied from authentication, but this may not take into account the privacy or privilege granularity requirements. Another view point is that providing compensation for the usage of the resources can be regarded as an act that fulfils the authorisation requirement. Thus, both the user and the provider of service have economic interests regarding the service usage and they should have a uniform view of the transactions taking place. Currently, there are no strong means in use to ensure this and the both parties have the possibility of cheating at the time of charging. This paper considers how inclusion of an authorisation mechanism into host identity protocol (HIP) can be used to provide a communication system that ensures correctness of service charging for both parties and better granularity of rights.

Read the paper · More papers on PaperTik