Journal on Communications ›› 2024, Vol. 45 ›› Issue (2): 40-53.doi: 10.11959/j.issn.1000-436x.2024023

• Papers • Previous Articles    

Cross-domain multi-copy of flow discovery mechanism based on dual certificate storage

Haiyang LUO1,2,3, Bin KUANG1,2,3, Shoukun GUO1,3, Lingcui ZHANG1,3, Ben NIU1,3, Fenghua LI1,2,3   

  1. 1 Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100085, China
    2 School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
    3 Key Laboratory of Cyberspace Security Defense, Beijing 100085, China
  • Revised:2023-12-13 Online:2024-02-01 Published:2024-02-01
  • Supported by:
    The National Key Research and Development Program of China(2021YFB3101301);The National Natural Science Foundation of China(62332018);The National Natural Science Foundation of China(61932015);Major Programs of the National Social Science Foundation of China(22&ZD147)

Abstract:

To solve the problems of the privacy information leakage caused by the deliberate or inadvertent retention of information when information was frequently exchanged across nodes and systems in a ubiquitous sharing environment, a cross-domain multi-copy of flow discovery mechanism based on dual certificate storage was proposed, which could trace the propagation path and channel, and construct a multi-copy propagation graph of the information.Depending on the timing and method of certification, the dual certification was comprised active circulation certification and passive operation certification.Before the information was shared, the information sharer actively recorded the propagation path and method to generate active circulation certification records.Before the information was operated, the system automatically recorded the propagation path to generate passive operational certification records.Compared with single certificate storage, the dual certificate storage could improve the integrity and authenticity of the constructed multi-copy propagation graph of information, and could detect nodes with abnormal certificate storage behavior and provide disposals.Based on the theory of social punishment, the effectiveness of abnormal certificate storage behavior detection and handling was demonstrated.A prototype system for multi-copy discovery of OFD with dual certificate storage is developed, the improvement of information dissemination graph construction integrity by the proposed mechanism is verified.

Key words: multi-copy discovery, certificate storage system, cross-domain flow, social punishment, propagation graph

CLC Number: 

No Suggested Reading articles found!