Tactical CAC profile for NATO OLP? Performance estimations for NATO OLP cryptographic evolution stage
Mikko Kiviharju, Arseny Kurnikov · 2016
The NATO Object Level Protection (OLP) is an approach to Allied data protection that aims to protect individual information objects separately. OLP has an evolution stage which involves the direct use of cryptography in this context, called Cryptographic Access Control. Using next-generation public-key encryption techniques called attribute-based encryption (ABE), RBAC policies may be directly encoded into encrypted objects and their respective key material. While attractive in theory, there is only little research on the performance impact of using different ABE solutions to determine their applicability in variety of military situations, for example tactical setups and military evolution stages of Internet-of-Things. Additionally, many of the early ABE schemes are lacking in their security model. Later schemes remedy these models, but with an additional impact in performance. In this paper, we will investigate the performance impact of using ABE with real-life military policies in the OLP context, both with proposed basic security model (selective security) ABE and newer full security ABE schemes. The investigation is performed by experimenting with existing ABE software libraries, such as PBC and Charm. We present both relative and absolute measures of bandwidth and computational performance of two, OLP-compatible ABE schemes.