Secure and Verifiable Policy Update Outsourcing for Big Data Access Control in the Cloud

Secure and Verifiable Policy Update Outsourcing for Big Data Access Control in the Cloud
复制标题

DOI:
10.1109/tpds.2014.2380373
复制
发表时间:
2015-12
影响因子:
5.3
通讯作者:
Kan Yang;Xiaohua Jia;Kui Ren
Kan Yang;Xiaohua Jia;Kui Ren
中科院分区:
计算机科学2区
文献类型:
--
作者:
Kan Yang;Xiaohua Jia;Kui Ren

文献摘要

被引文献

相似文献

由于大数据的量很高和速度,因此将大数据存储在云中是一个有效的选择,因为云具有存储大数据和处理大量用户访问请求的功能。基于属性的加密(ABE)是一种有前途的技术,可确保云中大数据的端到端安全性。但是,当使用ABE构建访问控制方案时,政策更新一直是一个具有挑战性的问题。一个微不足道的实现是让数据所有者检索数据并在新的访问策略下重新加入数据,然后将其发送回云。但是,这种方法会给数据所有者带来高度的通信开销和沉重的计算负担。在本文中,我们提出了一种新颖的方案,该方案可以通过动态策略更新云中的大数据来实现有效的访问控制。我们专注于为ABE系统开发外包政策更新方法。我们的方法可以避免传输加密数据,并通过使用带有旧访问策略的先前加密数据来最大程度地减少数据所有者的计算工作。此外,我们还提出了针对不同类型的访问策略更新算法的策略。最后,我们提出了一种高效且安全的方法,该方法允许数据所有者检查云服务器是否正确更新了密文。分析表明,我们的政策更新外包方案是正确,完整,安全和高效的。
Due to the high volume and velocity of big data, it is an effective option to store big data in the cloud, as the cloud has capabilities of storing big data and processing high volume of user access requests. Attribute-based encryption (ABE) is a promising technique to ensure the end-to-end security of big data in the cloud. However, the policy updating has always been a challenging issue when ABE is used to construct access control schemes. A trivial implementation is to let data owners retrieve the data and re-encrypt it under the new access policy, and then send it back to the cloud. This method, however, incurs a high communication overhead and heavy computation burden on data owners. In this paper, we propose a novel scheme that enabling efficient access control with dynamic policy updating for big data in the cloud. We focus on developing an outsourced policy updating method for ABE systems. Our method can avoid the transmission of encrypted data and minimize the computation work of data owners, by making use of the previously encrypted data with old access policies. Moreover, we also propose policy updating algorithms for different types of access policies. Finally, we propose an efficient and secure method that allows data owner to check whether the cloud server has updated the ciphertexts correctly. The analysis shows that our policy updating outsourcing scheme is correct, complete, secure and efficient.