TY - JOUR
T1 - ZTEI
T2 - 2022 IEEE Global Communications Conference, GLOBECOM 2022
AU - Fu, Peiyu
AU - Wu, Jun
AU - Lin, Xi
AU - Shen, Ao
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - The integration of satellite communication technology and terrestrial infrastructure has resulted in an un-precedented increase in network services covering the world. The main effect of the rapid growth of satellite networks is a broader range of data exchange and business interaction between the internal and external systems, making the network boundaries blur or even disappear. As a result, traditional passive security mechanisms based on dividing network boundaries cannot provide sufficient protection. To address this issue, in this paper, we propose a zero-trust and edge intelligence (ZTEI) empowered continuous authentication for satellite networks. We build an improved zero-trust architecture (ZTA) for satellite networks, which expands the traditional zero-trust concept to the multi-dimensional zero-trust that focuses on subject, object, environment, behavior, and physical entity. Then we propose a continuous authentication scheme in the proposed zero-trust architecture, enabling proactive and continuous authentication by periodically monitoring and re-evaluating variable attributes throughout the request lifecycle. Besides, in this scheme, we also design a Neural-Backed Decision Trees (NBDTs) based edge intelligence algorithm to improve the authentication accuracy. Finally, we build a testbed to evaluate the performance of the proposed architecture. Compared with the attribute-based access control (ABAC) under the traditional zero-trust architecture, our proposed architecture can improve the authentication accuracy of dynamic illegal requests by about 27%. In addition, according to standard network performance evaluation criteria, the loss of processing performance caused by our solution is also within an acceptable range.
AB - The integration of satellite communication technology and terrestrial infrastructure has resulted in an un-precedented increase in network services covering the world. The main effect of the rapid growth of satellite networks is a broader range of data exchange and business interaction between the internal and external systems, making the network boundaries blur or even disappear. As a result, traditional passive security mechanisms based on dividing network boundaries cannot provide sufficient protection. To address this issue, in this paper, we propose a zero-trust and edge intelligence (ZTEI) empowered continuous authentication for satellite networks. We build an improved zero-trust architecture (ZTA) for satellite networks, which expands the traditional zero-trust concept to the multi-dimensional zero-trust that focuses on subject, object, environment, behavior, and physical entity. Then we propose a continuous authentication scheme in the proposed zero-trust architecture, enabling proactive and continuous authentication by periodically monitoring and re-evaluating variable attributes throughout the request lifecycle. Besides, in this scheme, we also design a Neural-Backed Decision Trees (NBDTs) based edge intelligence algorithm to improve the authentication accuracy. Finally, we build a testbed to evaluate the performance of the proposed architecture. Compared with the attribute-based access control (ABAC) under the traditional zero-trust architecture, our proposed architecture can improve the authentication accuracy of dynamic illegal requests by about 27%. In addition, according to standard network performance evaluation criteria, the loss of processing performance caused by our solution is also within an acceptable range.
KW - continuous authentication
KW - edge intelligence
KW - satellite networks
KW - Zero trust
UR - http://www.scopus.com/inward/record.url?scp=85146920373&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85146920373&partnerID=8YFLogxK
U2 - 10.1109/GLOBECOM48099.2022.10000958
DO - 10.1109/GLOBECOM48099.2022.10000958
M3 - Conference article
AN - SCOPUS:85146920373
SN - 2334-0983
SP - 2376
EP - 2381
JO - Proceedings - IEEE Global Communications Conference, GLOBECOM
JF - Proceedings - IEEE Global Communications Conference, GLOBECOM
Y2 - 4 December 2022 through 8 December 2022
ER -