跳到主要导航 跳到搜索 跳到主要内容

DSP re-encryption based access control enforcement management mechanism in DaaS

  • Shanghai University of Electric Power

科研成果: 期刊稿件文章同行评审

摘要

With the popular use of service-oriented technologies, Database as a Service(DaaS) paradigm is becoming a more practical and useful model for those enterprises who can't afford the expensive DBMS products. However, access control management by the database service provider(DSP) in this paradigm is challenged because the DSP may be untrusted for the delegated data contents. So it is important to design an access control mechanism which can couple with the delegated encrypted database to efficiently improve the usability of the system and help to prevent theft of sensitive and critical data. In this paper, we present a novel approach to implement flexible access control enforcement management by designing a DSP re-encryption mechanism. Our approach not only can implement the selective authorization on the encrypted data, but also can relieve the client users from the complex key derivation procedure. The underlying idea of our approach is that the DSP uses different re-encryption keys for users of the system to implement flexible access control enforcement management under the DSP re-encryption mechanism. We demonstrate the efficiency and security of our flexible access control enforcement management, in the end we analyze and resolve the possible attacks and information disclosure.

源语言英语
页(从-至)28-41
页数14
期刊International Journal of Network Security
15
1
出版状态已出版 - 1月 2013

学术指纹

探究 'DSP re-encryption based access control enforcement management mechanism in DaaS' 的科研主题。它们共同构成独一无二的学术指纹。

引用此