Secure attribute-based systems

Secure attribute-based systems
复制标题

DOI:
10.3233/jcs-2009-0383
复制
发表时间:
2010-01-01
影响因子:
1.2
通讯作者:
Waters, Brent
Waters, Brent
中科院分区:
其他
文献类型:
--
作者:
Pirretti, Matthew;Traynor, Patrick;Waters, Brent

文献摘要

被引文献

相似文献

属性对其所分配的数据进行定义、分类或注释。然而,面对不同的访问需求和环境,传统的属性架构和密码系统难以提供安全性。在本文中,我们介绍一种基于新兴的基于属性加密(ABE)原语的新型安全信息管理架构。定义并阐述了一个满足复杂策略需求的策略系统。基于这些策略的需求,我们提出了密码学优化方法,极大地提高了执行效率。我们进一步探讨了在两个提议的应用中此类策略的使用:一个符合《健康保险流通与责任法案》(HIPAA)的分布式文件系统和一个社交网络。对ABE原语的性能分析和特性描述表明,与先前提出的构造相比,能够将密码学成本降低多达98%。通过这一点,我们证明我们的属性系统是在大型、松散耦合的分布式系统中安全管理信息的一种高效解决方案。
Attributes define, classify, or annotate the datum to which they are assigned. However, traditional attribute architectures and cryptosystems are ill-equipped to provide security in the face of diverse access requirements and environments. In this paper, we introduce a novel secure information management architecture based on emerging attribute-based encryption (ABE) primitives. A policy system that meets the needs of complex policies is defined and illustrated. Based on the needs of those policies, we propose cryptographic optimizations that vastly improve enforcement efficiency. We further explore the use of such policies in two proposed applications: a HIPAA compliant distributed file system and a social network. A performance analysis and characterization of ABE primitives demonstrates the ability to reduce cryptographic costs by as much as 98% over previously proposed constructions. Through this, we demonstrate that our attribute system is an efficient solution for securely managing information in large, loosely-coupled, distributed systems.