SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and Analytics

被引:2
|
作者
Xue, Tao [1 ,2 ]
Wen, Yu [1 ]
Luo, Bo [3 ]
Li, Gang [4 ]
Li, Yingjiu [5 ]
Zhang, Boyang [1 ]
Zheng, Yang [1 ]
Hu, Yanfei [1 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100045, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 101408, Peoples R China
[3] Univ Kansas, Dept Elect Engn & Comp Sci, Lawrence, KS 66045 USA
[4] Deakin Univ, Ctr Cyber Secur Res & Innovat, Geelong, Vic 3217, Australia
[5] Univ Oregon, Dept Comp & Informat Sci, Eugene, OR 97403 USA
关键词
Sparks; Access control; Data analysis; Data models; Big Data; Optimization; Hospitals; Spark; big data; access control; data sharing; data protection; purpose; BIG-DATA; FLOW;
D O I
10.1109/TDSC.2022.3149544
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing purpose and data operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead.
引用
收藏
页码:1104 / 1123
页数:20
相关论文
共 50 条
  • [41] A fine-grained data access control algorithm in cloud computing
    Han, Dezhi
    Wu, Shuai
    Bi, Kun
    Huazhong Keji Daxue Xuebao (Ziran Kexue Ban)/Journal of Huazhong University of Science and Technology (Natural Science Edition), 2012, 40 (SUPPL.1): : 245 - 248
  • [42] On the Insecurity of a Method for Providing Secure and Private Fine-Grained Access to Outsourced Data
    Rial, Alfredo
    2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 407 - 413
  • [43] Fine-grained data access control for distributed sensor networks
    Hur, Junbeom
    WIRELESS NETWORKS, 2011, 17 (05) : 1235 - 1249
  • [44] A Secure and Efficient Revocation Scheme for Fine-Grained Access Control in Cloud Storage
    Lv, Zhiquan
    Hong, Cheng
    Zhang, Min
    Feng, Dengguo
    2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [45] A Secure Remote Monitoring Framework Supporting Efficient Fine-Grained Access Control and Data Processing in IoT
    Chen, Yaxing
    Sun, Wenhai
    Zhang, Ning
    Zheng, Qinghua
    Lou, Wenjing
    Hou, Y. Thomas
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT I, 2018, 254 : 3 - 21
  • [46] Secure Cloud-Assisted Data Pub/Sub Service With Fine-Grained Bilateral Access Control
    Zhang, Kai
    Wang, Xiwen
    Ning, Jianting
    Gong, Junqing
    Huang, Xinyi
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5286 - 5301
  • [47] Secure Fine-Grained Data Access Control Over Multiple Cloud Server Based Healthcare Applications
    Deshmukh, Nilam Manikrao
    Kumar, Santosh
    Shirsath, Rakesh
    2019 5TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, CONTROL AND AUTOMATION (ICCUBEA), 2019,
  • [48] Lightweight, verifiable and revocable EHRs sharing with fine-grained bilateral access control
    Zhang, Kai
    Chen, Tao
    Chen, Siyuan
    Wei, Lifei
    Ning, Jianting
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (07): : 9957 - 9973
  • [49] Achieving fine-grained and flexible access control on blockchain-based data sharing for the Internet of Things
    Wang, Ruimiao
    Wang, Xiaodong
    Yang, Wenti
    Yuan, Shuai
    Guan, Zhitao
    CHINA COMMUNICATIONS, 2022, 19 (06) : 22 - 34
  • [50] Achieving Fine-Grained and Flexible Access Control on Blockchain-Based Data Sharing for the Internet of Things
    Ruimiao Wang
    Xiaodong Wang
    Wenti Yang
    Shuai Yuan
    Zhitao Guan
    China Communications, 2022, (06) : 22 - 34