跳到主要导航 跳到搜索 跳到主要内容

DualAcE: FINE-grained dual access control enforcement with multi-privacy guarantee in DaaS

  • Xiuxia Tian*
  • , Ling Huang
  • , Yong Wang
  • , Chaofeng Sha
  • , Xiaoling Wang
  • *此作品的通讯作者
  • Shanghai University of Electric Power
  • University of California at Berkeley
  • Texas A&M University
  • Fudan University

科研成果: 期刊稿件文章同行评审

摘要

Database as a service (DaaS), a new paradigm of software as a service based on cloud computing, is attracting more and more enterprises (data owners) to delegate their database management to a professional third party (database service provider) such as Amazon Web Services and Rackspace. Data owners in DaaS lose control of their sensitive data, which are stored in the delegated database and managed by the untrusted database service provider. Therefore, many encryption-based approaches including attribute-based encryption were proposed to implement fine-grained access control in DaaS scenarios. However, most of the proposed access control enforcement approaches only support one or two of the following privacy guarantees: data privacy, policy privacy and key privacy. In this paper, we first propose a novel concept of DualAcE: a flexible fine-grained dual access control enforcement mechanism in DaaS by efficiently combining the ciphertext-policy attribute-set-based encryption with database service provider re-encryption into a DaaS paradigm. The proposed mechanism has implemented dual access control enforcement with multi-privacy guarantee: data privacy in delegated database, policy privacy in delegated authorization table and key privacy in key distribution process.We describe the security and efficiency analysis through cryptography theory and experimental results.

源语言英语
页(从-至)1494-1508
页数15
期刊Security and Communication Networks
8
8
DOI
出版状态已出版 - 25 5月 2015

学术指纹

探究 'DualAcE: FINE-grained dual access control enforcement with multi-privacy guarantee in DaaS' 的科研主题。它们共同构成独一无二的学术指纹。

引用此