SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and Analytics

被引:2
|
作者
Xue, Tao [1 ,2 ]
Wen, Yu [1 ]
Luo, Bo [3 ]
Li, Gang [4 ]
Li, Yingjiu [5 ]
Zhang, Boyang [1 ]
Zheng, Yang [1 ]
Hu, Yanfei [1 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100045, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 101408, Peoples R China
[3] Univ Kansas, Dept Elect Engn & Comp Sci, Lawrence, KS 66045 USA
[4] Deakin Univ, Ctr Cyber Secur Res & Innovat, Geelong, Vic 3217, Australia
[5] Univ Oregon, Dept Comp & Informat Sci, Eugene, OR 97403 USA
关键词
Sparks; Access control; Data analysis; Data models; Big Data; Optimization; Hospitals; Spark; big data; access control; data sharing; data protection; purpose; BIG-DATA; FLOW;
D O I
10.1109/TDSC.2022.3149544
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing purpose and data operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead.
引用
收藏
页码:1104 / 1123
页数:20
相关论文
共 50 条
  • [21] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou Yousheng
    Chen Lujun
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (07) : 1856 - 1863
  • [22] DACSC: Dynamic and Fine-Grained Access Control for Secure Data Collaboration in Cloud Computing
    Huang, Qinlong
    Li, Nan
    Yang, Yixian
    2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [23] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou, Yousheng
    Chen, Lüjun
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2021, 43 (07): : 1856 - 1863
  • [24] A fine-grained and secure health data sharing scheme based on blockchain
    Chen, Jiahao
    Yin, Xinchun
    Ning, Jianting
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (09)
  • [25] Towards secure and fine-grained data sharing over cloud platform
    Fuyuan Song
    Xiaowei Sun
    Yunlong Gao
    Qin Jiang
    Zhangjie Fu
    Frontiers of Computer Science, 2025, 19 (6)
  • [26] Light weight and fine-grained access mechanism for secure access to outsourced data*
    Jahan, Mosarrat
    Seneviratne, Suranga
    Roy, Partha Sarathi
    Sakurai, Kouichi
    Seneviratne, Aruna
    Jha, Sanjay
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (23):
  • [27] The Fine-Grained Security Access Control of Spatial Data
    Ma, Fuguang
    Gao, Yong
    Yan, Menglong
    Xu, Fuchun
    Liu, Ding
    2010 18TH INTERNATIONAL CONFERENCE ON GEOINFORMATICS, 2010,
  • [28] Secure and Light Weight Fine-grained Access Mechanism for Outsourced Data
    Jahan, Mosarrat
    Roy, Partha Sarathi
    Sakurai, Kouichi
    Seneviratne, Aruna
    Jha, Sanjay
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 201 - 209
  • [29] Method for Providing Secure and Private Fine-grained Access to Outsourced Data
    Jahan, Mosarrat
    Rezvani, Mohsen
    Seneviratne, Aruna
    Jha, Sanjay
    40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 406 - 409
  • [30] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    The Journal of China Universities of Posts and Telecommunications, 2015, (02) : 38 - 43