Netinfo Security ›› 2021, Vol. 21 ›› Issue (6): 19-25.doi: 10.3969/j.issn.1671-1122.2021.06.003

Previous Articles     Next Articles

Design of DDS Secure Communication Middleware Based on Security Negotiation

SHEN Zhuowei1,2(), GAO Peng1,2, XU Xinyu1,2   

  1. 1. School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
    2. Key Laboratory of Computer Network and Information Integration(Southeast University), Ministry of Education, Nanjing 211189, China;
  • Received:2021-02-25 Online:2021-06-10 Published:2021-07-01
  • Contact: SHEN Zhuowei E-mail:zwshen@seu.edu.cn

Abstract:

In response to the security threats faced by distributed real-time applications based on DDS in critical areas, a PKI based DDS secure communication middleware scheme is proposed, which adopts plug-in design and supports the functions of identity authentication, access control and data encryption and decryption. The scheme not only keeps the APIs consistent with the original DDS middleware, but also integrates the security negotiation process with the discovery mechanism of DDS. By using the customized security QoS and standardized QoS negotiation mechanism, the security service level and encryption algorithm can be chosen and configured flexibly. The confidentiality of data distribution is achieved by combing asymmetric encryption and symmetric encryption. Theoretical analysis and prototype system test show that the proposed DDS middleware can solve the security threats such as unauthorized subscription, unauthorized publishing and insecure channel transmission in the process of data distribution, and the delay is only slightly increased compared with the original DDS middleware. This scheme gives consideration to both security and efficiency.

Key words: data distribution service, middleware, identity authentication, access control, data confidentiality

CLC Number: