SECProv: Trustworthy and Efficient Provenance Management in the Cloud

SECProv: Trustworthy and Efficient Provenance Management in the Cloud
复制标题

DOI:
10.1109/infocom.2018.8485824
复制
发表时间:
2018-04
期刊:
IEEE INFOCOM 2018 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
Shams Zawoad;Ragib Hasan;M. Islam
Shams Zawoad;Ragib Hasan;M. Islam
中科院分区:
其他
文献类型:
--
作者:
Shams Zawoad;Ragib Hasan;M. Islam

文献摘要

被引文献

相似文献

云的黑匣子性质导致人们对云缺乏信任。由于来源可以提供实体的完整历史记录,因此对数据、应用程序或工作流进行可靠的来源管理可以使云更加负责任。目前对云溯源的研究主要集中在收集溯源记录并信任云提供商管理溯源记录。但是,不诚实的云提供商可以更改来源记录,因为这些记录存储在云提供商的控制范围内。为了解决这个问题,我们首先提出了 CloProv——一种来源模型,用于捕获云中任何类型实体的完整来源。我们分析了 CloProv 模型上的威胁,考虑到恶意用户和不诚实的云提供商之间的勾结。基于威胁模型,我们提出了一种基于云的、多用户、共享数据存储系统的安全数据溯源方案——SECProv。我们将SECProv与开源云框架OpenStack Swift的对象存储模块集成,并分析了所提出方案的效率。
The black-box nature of clouds introduces a lack of trusts in clouds. Since provenance can provide a complete history of an entity, trustworthy provenance management for data, application, or workflow can make the cloud more accountable. Current research on cloud provenance mainly focuses on collecting provenance records and trusting the cloud providers in managing the provenance records. However, a dishonest cloud provider can alter the provenance records, as the records are stored within the control of the cloud provider. To solve this problem, we first propose CloProv - a provenance model to capture the complete provenance of any type of entities in the cloud. We analyze the threats on the CloProv model considering collusion among malicious users and dishonest cloud providers. Based on the threat model, we propose a secure data provenance scheme - SECProv for cloud-based, multi-user, shared data storage systems. We integrate SECProv with the object storage module of an open source cloud framework - OpenStack Swift and analyze the efficiency of the proposed scheme.