Exploring Architectures for Cryptographic Access Control Enforcement in the Cloud for Fun and Optimization

Exploring Architectures for Cryptographic Access Control Enforcement in the Cloud for Fun and Optimization
复制标题

DOI:
10.1145/3320269.3384767
复制
发表时间:
2020-10
期刊:
Proceedings of the 15th ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Stefano Berlato;R. Carbone;Adam J. Lee;Silvio Ranise
Stefano Berlato;R. Carbone;Adam J. Lee;Silvio Ranise
中科院分区:
其他
文献类型:
--
作者:
Stefano Berlato;R. Carbone;Adam J. Lee;Silvio Ranise

文献摘要

被引文献

相似文献

为了促进组织采用云计算,加密访问控制(CAC)是控制用户之间数据共享的明显解决方案,同时防止部分受信任的云服务提供商(CSP)访问敏感数据。事实上,在文献中已经提出了几种CAC方案。尽管存在差异,但可用的解决方案都是基于一组共同的实体-例如,在不同(安全)域中操作的调解用户对加密数据的访问的数据存储服务或代理,例如,内部部署或CSP。然而,大多数CAC方案假设将实体固定分配给域;这具有未明确的安全性和可用性影响,并且可能在具有特定要求的某些场景中不适当地使用CAC方案。例如,假设代理在组织的场所运行,可以避免供应商锁定效应,但可能会严重破坏可伸缩性。据我们所知,以前的工作没有考虑如何选择最好的可能架构(即,实体到域的分配)来部署用于给定场景的要求的CAC方案。在本文中,我们提出了一种方法,以帮助管理员在探索不同的体系结构的CAC计划为一个给定的场景。我们这样做,通过确定可能的体系结构的CAC计划在文献中,并正式在简单的集合论。这使我们能够减少选择最合适的架构,满足所考虑的情况下产生的异构的一组要求的问题,多目标优化问题(MOOP)的国家的最先进的求解器可以调用。最后,我们将展示如何使用解决MOOP的能力来构建一个原型工具,帮助管理员初步执行“假设”分析,以探索各种架构之间的权衡,然后使用可用的标准和工具(如TOSCA和Cloudify)在多个CSP中进行自动化部署。
To facilitate the adoption of cloud by organizations, Cryptographic Access Control (CAC) is the obvious solution to control data sharing among users while preventing partially trusted Cloud Service Providers (CSP) from accessing sensitive data. Indeed, several CAC schemes have been proposed in the literature. Despite their differences, available solutions are based on a common set of entities---e.g., a data storage service or a proxy mediating the access of users to encrypted data---that operate in different (security) domains---e.g., on-premise or the CSP. However, the majority of the CAC schemes assume a fixed assignment of entities to domains; this has security and usability implications that are not made explicit and can make inappropriate the use of a CAC scheme in certain scenarios with specific requirements. For instance, assuming that the proxy runs at the premises of the organization avoids the vendor lock-in effect but may substantially undermine scalability. To the best of our knowledge, no previous work considers how to select the best possible architecture (i.e., the assignment of entities to domains) to deploy a CAC scheme for the requirements of a given scenario. In this paper, we propose a methodology to assist administrators in exploring different architectures of CAC schemes for a given scenario. We do this by identifying the possible architectures underlying the CAC schemes available in the literature and formalizing them in simple set theory. This allows us to reduce the problem of selecting the most suitable architecture satisfying a heterogeneous set of requirements arising from the considered scenario to a Multi-Objective Optimization Problem (MOOP) for which state-of-the-art solvers can be invoked. Finally, we show how the capability of solving the MOOP can be used to build a prototype tool assisting administrators to preliminary perform a "What-if'' analysis to explore the trade-offs among the various architectures and then use available standards and tools (such as TOSCA and Cloudify) for automated deployment in multiple CSPs.