SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and Analytics

被引:2
|
作者
Xue, Tao [1 ,2 ]
Wen, Yu [1 ]
Luo, Bo [3 ]
Li, Gang [4 ]
Li, Yingjiu [5 ]
Zhang, Boyang [1 ]
Zheng, Yang [1 ]
Hu, Yanfei [1 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100045, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 101408, Peoples R China
[3] Univ Kansas, Dept Elect Engn & Comp Sci, Lawrence, KS 66045 USA
[4] Deakin Univ, Ctr Cyber Secur Res & Innovat, Geelong, Vic 3217, Australia
[5] Univ Oregon, Dept Comp & Informat Sci, Eugene, OR 97403 USA
关键词
Sparks; Access control; Data analysis; Data models; Big Data; Optimization; Hospitals; Spark; big data; access control; data sharing; data protection; purpose; BIG-DATA; FLOW;
D O I
10.1109/TDSC.2022.3149544
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing purpose and data operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead.
引用
收藏
页码:1104 / 1123
页数:20
相关论文
共 50 条
  • [1] Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
    Xu, Shengmin
    Yang, Guomin
    Mu, Yi
    Deng, Robert H.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (08) : 2101 - 2113
  • [2] Achieving fine-grained access control for secure data sharing on cloud servers
    Wang, Guojun
    Liu, Qin
    Wu, Jie
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2011, 23 (12): : 1443 - 1464
  • [3] GuardSpark plus plus : Fine-Grained Purpose-Aware Access Control for Secure Data Sharing and Analysis in Spark
    Xue, Tao
    Wen, Yu
    Luo, Bo
    Zhang, Boyang
    Zheng, Yang
    Hu, Yanfei
    Li, Yingjiu
    Li, Gang
    Meng, Dan
    36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020), 2020, : 582 - 596
  • [4] Encryption-Based Secure Sharing of Data with Fine-Grained Access Control in Public Clouds
    Selvam, L.
    Kumar, P. Mohan
    Renjith, J. Arokia
    JOURNAL OF APPLIED SECURITY RESEARCH, 2014, 9 (02) : 172 - 184
  • [5] A Secure Revocable Fine-Grained Access Control and Data Sharing Scheme for SCADA in IIoT Systems
    Zhang, Weiting
    Zhang, Hanyi
    Fang, Liming
    Liu, Zhe
    Ge, Chunpeng
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (03) : 1976 - 1984
  • [6] Fine-grained Access Control and Revocation for Sharing Data on Clouds
    Tu, Shan-shan
    Niu, Shao-zhang
    Li, Hui
    Yun Xiao-ming
    Li, Meng-jiao
    2012 IEEE 26TH INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS & PHD FORUM (IPDPSW), 2012, : 2146 - 2155
  • [7] The Queen's Guard: A Secure Enforcement of Fine-grained Access Control In Distributed Data Analytics Platforms
    Shaon, Fahad
    Rahaman, Sazzadur
    Kantarcioglu, Murat
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 241 - 255
  • [8] Fine-grained Encryption for Secure Research Data Sharing
    Reis, Lucio H. A.
    de Oliveira, Marcela T.
    Olabarriaga, Silvia D.
    2022 IEEE 35TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS (CBMS), 2022, : 465 - 470
  • [9] A Fine-Grained Access Control Model with Secure Label on Data Resource
    Gao, Lijie
    Liu, Lianzhong
    Jin, Ze
    Han, Chunyan
    2013 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), 2013, : 14 - 18
  • [10] Secure Time Series Data Sharing with Fine-Grained Access Control in Cloud-Enabled IIoT
    Halder, Subir
    Newe, Thomas
    PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,