On the security of NDN's privacy access control framework
Jianhong Zhang, Jie Wei · 2025
Named Data Networking (NDN) is an emerging network architecture that fundamentally shifts from the conventional Internet communication model by focusing on data-centricity. However, the openness of networks poses a significant risk of unauthorized access to sensitive data, thereby challenging the preservation of data security and integrity. To address this issue, Nazatul et al. have recently proposed a role-based access control framework (NDN-RBE) tailored to enhance data access security within the NDN environment. Despite their assertion of the NDN-RBE scheme's ability to ensure secure data access control through identity verification based on anonymous signatures, our analysis reveals inherent vulnerabilities during the verification phase, rendering it susceptible to signature forgery attacks. This paper aims to provide a comprehensive examination of signature forgery attack methodologies, delving into the underlying reasons for its insecurity. Furthermore, it concludes by presenting practical recommendations for enhancing the security robustness of the NDN-RBE framework. If the vulnerabilities are addressed, stakeholders can better safeguard data integrity and confidentiality within the NDN ecosystem, ensuring its viability in the evolving landscape of network architectures.