Scalable and Secure Access Control Policy Update for Outsourced Big Data

Scalable and Secure Access Control Policy Update for Outsourced Big Data
复制标题

外包大数据的可扩展且安全的访问控制策略更新

DOI:
10.1016/j.future.2017.06.014
复制
发表时间:
2017
期刊:
Future Generation Computer Systems
影响因子:
--
通讯作者:
Hiroyuki Sato
Hiroyuki Sato
中科院分区:
--
文献类型:
--
作者:
Somchart Fugkeaw;Hiroyuki Sato

文献摘要

被引文献

相似文献

在云计算等数据外包环境中,基于密文策略的属性加密(CP-ABE)能够根据多个用户的用户属性对共享数据进行有效的密钥管理,是最有效的数据访问控制方法之一。然而,处理策略更新限制了CP-ABE的效率。在CP-ABE方案中,访问策略被用作数据加密的核心元素。因此,如果更新了策略,数据所有者需要重新加密文件并将其发送回云端。这在数据所有者侧引起包括计算、通信和维护成本的开销。如果外包环境致力于“大数据”,计算和通信成本非常昂贵。在本文中,我们扩展了我们的访问控制方案的能力:C-CP-ARBE能够支持安全和灵活的策略更新在大数据外包环境。我们开发了一个安全的策略更新算法,并提出了一个非常轻量级的代理重新加密(VL-PRE)技术,使策略更新在云中进行,在一个有效的和计算成本有效的方式。最后,我们证明了我们所提出的方案的效率和性能,通过实施。
Ciphertext Policy Attribute-based Encryption (CP-ABE) is proven to be one of the most effective approaches to data access control in data outsourcing environment such as cloud computing since it provides efficient key management based on user attributes of multiple users in accessing shared data. However, dealing with policy update limits the efficiency of the CP-ABE. In CP-ABE scheme, the access policy is used as a core element for data encryption. Hence, if the policy is updated, the data owner needs to re-encrypt files and send them back to the cloud. This incurs overheads including computation, communication, and maintenance cost at the data owner side. The computation and communication cost are very expensive if the outsourcing environment is devoted to “big data”. In this paper, we extend the capability of our access control scheme: C-CP-ARBE to be capable of supporting secure and flexible policy updates in the big data outsourcing environment. We develop a secure policy updating algorithm and propose a very lightweight proxy re-encryption (VL-PRE) technique to enable the policy updating to be done in the cloud in an efficient and computationally cost effective manner. Finally, we demonstrate the efficiency and performance of our proposed scheme through the implementation.