Attribute-Based Access Control with Efficient Revocation in Data Outsourcing Systems

Attribute-Based Access Control with Efficient Revocation in Data Outsourcing Systems
复制标题

DOI:
10.1109/tpds.2010.203
复制
发表时间:
2011-07-01
影响因子:
5.3
通讯作者:
Noh, Dong Kun
Noh, Dong Kun
中科院分区:
计算机科学2区
文献类型:
--
作者:
Hur, Junbeom;Noh, Dong Kun

文献摘要

被引文献

相似文献

在数据外包场景中,一些最具挑战性的问题是授权策略的执行以及策略更新的支持。密文策略基于属性加密是解决这些问题的一种有前景的密码学方案,用于在外包数据上执行数据所有者定义的访问控制策略。然而,在外包架构中应用基于属性的加密这一问题在属性和用户撤销方面带来了若干挑战。在本文中,我们提出一种使用密文策略基于属性加密的访问控制机制,以实现具有高效属性和用户撤销能力的访问控制策略。细粒度的访问控制可通过双重加密机制实现,该机制利用了基于属性的加密以及每个属性组中的选择性组密钥分配。我们演示了如何应用所提出的机制来安全地管理外包数据。分析结果表明,所提出的方案在数据外包系统中是高效且安全的。
Some of the most challenging issues in data outsourcing scenario are the enforcement of authorization policies and the support of policy updates. Ciphertext-policy attribute-based encryption is a promising cryptographic solution to these issues for enforcing access control policies defined by a data owner on outsourced data. However, the problem of applying the attribute-based encryption in an outsourced architecture introduces several challenges with regard to the attribute and user revocation. In this paper, we propose an access control mechanism using ciphertext-policy attribute-based encryption to enforce access control policies with efficient attribute and user revocation capability. The fine-grained access control can be achieved by dual encryption mechanism which takes advantage of the attribute-based encryption and selective group key distribution in each attribute group. We demonstrate how to apply the proposed mechanism to securely manage the outsourced data. The analysis results indicate that the proposed scheme is efficient and secure in the data outsourcing systems.