12.07.2015 Views

Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008

Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008

Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

security tasks (authentication and identitymanagement, intrusion d<strong>et</strong>ection, superdistributionand legacy) that they have kickedoffrecently.Future Work and ConclusionWe will use Data Rights Management (DRM) toaddress security issues of P2Pim@ge project.Our Federated Rights Expression Model(FORM) [1], allows a content provider todecide to trust external rendering rights andexternal identities. We then go furtherintroducing identity providers, actionsproviders as we consider content providers.Thus, all kind of providers can define licensesspecifying what can be done with the contentthey provide. FORM defines a new licensemodel and interpr<strong>et</strong>ation mechanism takinginto account all licenses issued by a federationof content providers.We will also make use of our new superdistributionmodel called Onion PolicyAdministration Model (OPA) [2]. OPA providesa compl<strong>et</strong>e traceability of the contentdistribution. The content must keep track of allthird-parties it crosses in the distribution chain.In this case, everyone can distribute thecontent and define a new license without anyrestriction. This administration model is easierto grasp than other super-distributionmechanisms especially when many distributorsare involved in the super-distribution chain ofgiven information content as it is the case in aP2P system. OPA is an adequate administrationmodel upon FORM as it can be extended tohandle data, m<strong>et</strong>hods and user profiles aswell.The protocols associated to FORM and OPA willbe specified, customized to P2Pim@ageplatform and implemented.The authentication of P2Pim@ge actors andthe federation of identity of pairs are keyproblems in the projects. We intend to use ourresearch works on interoperability of securitypolicies, and developments performed in ourplatform Protekto (see the next she<strong>et</strong>) toleverage P2Pim@ge tasks related to theseaspects.References[1] Thierry Sans, Frédéric Cuppens and NoraCuppens-Boulahia. FORM: A Federated RightsExpression Model for Open DRM Frameworks.ASIAN'06. 11th Annual Asian ComputingScience Conference, focusing on SecureSoftware and Related Issues. Tokyo, Japan.December 2006.[2] Thierry Sans, Frédéric Cuppens and NoraCuppens-Boulahia. OPA: Onion PolicyAdministration Model - Another approach tomanage rights in DRM. IFIP/SEC 2007, 21stIFIP TC-11 International Information SecurityConference. Sandton, South Africa. May 2007.Pracom’s Annual Report <strong>2008</strong> 59

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!