PRShare: A Framework for Privacy-preserving, Interorganizational Data Sharing

PRShare: A Framework for Privacy-preserving, Interorganizational Data Sharing
复制标题

DOI:
10.1145/3531225
复制
发表时间:
2022-04
影响因子:
2.3
通讯作者:
Lihi Idan;J. Feigenbaum
Lihi Idan;J. Feigenbaum
中科院分区:
计算机科学4区
文献类型:
--
作者:
Lihi Idan;J. Feigenbaum

文献摘要

被引文献

相似文献

我们考虑组织间数据共享的任务,其中数据所有者、数据客户端和数据主体具有不同的,有时是相互竞争的隐私问题。出现此问题的一个现实场景涉及执法部门对电话呼叫元数据的使用:数据所有者是一家电话公司,数据客户端是执法机构,数据主体是拨打电话的个人。这类场景中的一个关键挑战是,每个组织都使用自己的一组专有的组织内部属性来描述共享数据;这些属性不能与其他组织共享。此外,数据访问策略由多方确定,并且可以使用与所有者指定数据所使用的属性不能直接比较的属性来指定。我们提出了一个系统架构和一套协议,以促进动态和有效的组织间数据共享,同时允许各方使用自己的专有属性集来描述共享数据,并保持数据记录和专有组织内属性的机密性。我们引入了一种新的基于属性的加密与遗忘属性转换(OTABE)技术,该技术在我们的解决方案中起着至关重要的作用。这种基于属性的加密的扩展使用半可信代理来实现属于不同组织的专有属性之间的动态和不经意的转换;它支持隐藏访问策略、直接撤销以及细粒度的、以数据为中心的键和查询。我们证明了基于otabe的框架在标准模型中是安全的,并提供了两个真实的用例。
We consider the task of interorganizational data sharing, in which data owners, data clients, and data subjects have different and sometimes competing privacy concerns. One real-world scenario in which this problem arises concerns law-enforcement use of phone-call metadata: The data owner is a phone company, the data clients are law-enforcement agencies, and the data subjects are individuals who make phone calls. A key challenge in this type of scenario is that each organization uses its own set of proprietary intraorganizational attributes to describe the shared data; such attributes cannot be shared with other organizations. Moreover, data-access policies are determined by multiple parties and may be specified using attributes that are not directly comparable with the ones used by the owner to specify the data. We propose a system architecture and a suite of protocols that facilitate dynamic and efficient interorganizational data sharing, while allowing each party to use its own set of proprietary attributes to describe the shared data and preserving the confidentiality of both data records and proprietary intraorganizational attributes. We introduce the novel technique of Attribute-Based Encryption with Oblivious Attribute Translation (OTABE), which plays a crucial role in our solution. This extension of attribute-based encryption uses semi-trusted proxies to enable dynamic and oblivious translation between proprietary attributes that belong to different organizations; it supports hidden access policies, direct revocation, and fine-grained, data-centric keys and queries. We prove that our OTABE-based framework is secure in the standard model and provide two real-world use cases.