Security, Privacy, and Access Control in Information-Centric Networking: A Survey

Information-Centric Networking (ICN) is a new networking paradigm, which\nreplaces the widely used host-centric networking paradigm in communication\nnetworks (e.g., Internet, mobile ad hoc networks) with an information-centric\nparadigm, which prioritizes the delivery of named content, oblivious of the\ncontents origin. Content and client security are more intrinsic in the ICN\nparadigm versus the current host centric paradigm where they have been\ninstrumented as an after thought. By design, the ICN paradigm inherently\nsupports several security and privacy features, such as provenance and identity\nprivacy, which are still not effectively available in the host-centric\nparadigm. However, given its nascency, the ICN paradigm has several open\nsecurity and privacy concerns, some that existed in the old paradigm, and some\nnew and unique. In this article, we survey the existing literature in security\nand privacy research sub-space in ICN. More specifically, we explore three\nbroad areas: security threats, privacy risks, and access control enforcement\nmechanisms.\n We present the underlying principle of the existing works, discuss the\ndrawbacks of the proposed approaches, and explore potential future research\ndirections. In the broad area of security, we review attack scenarios, such as\ndenial of service, cache pollution, and content poisoning. In the broad area of\nprivacy, we discuss user privacy and anonymity, name and signature privacy, and\ncontent privacy. ICN's feature of ubiquitous caching introduces a major\nchallenge for access control enforcement that requires special attention. In\nthis broad area, we review existing access control mechanisms including\nencryption-based, attribute-based, session-based, and proxy re-encryption-based\naccess control schemes. We conclude the survey with lessons learned and scope\nfor future work.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC