Secure Cloud-Assisted Data Pub/Sub Service With Fine-Grained Bilateral Access Control

被引:1
|
作者
Zhang, Kai [1 ]
Wang, Xiwen [1 ]
Ning, Jianting [2 ,3 ]
Gong, Junqing [4 ]
Huang, Xinyi [2 ,5 ]
机构
[1] Shanghai Univ Elect Power, Coll Comp Sci & Technol, Shanghai 201306, Peoples R China
[2] Fujian Normal Univ, Coll Comp & Cyber Secur, Key Lab Analyt Math & Applicat, Minist Educ, Fuzhou 350007, Peoples R China
[3] City Univ Macau, Fac Data Sci, Macau, Peoples R China
[4] East China Normal Univ, Software Engn Inst, Shanghai 200062, Peoples R China
[5] Hong Kong Univ Sci & Technol Guangzhou, Thrust Artificial Intelligence Informat Hub, Guangzhou 511453, Peoples R China
基金
中国国家自然科学基金;
关键词
Access control; Costs; Encryption; Time complexity; Data privacy; Privacy; Task analysis; Data publish/subscribe service; searchable encryption; matchmaking encryption; bilateral access control; SEARCHABLE SYMMETRIC-ENCRYPTION; PUBLISH/SUBSCRIBE SYSTEMS; INTERNET; SUPPORT;
D O I
10.1109/TIFS.2023.3303720
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Secure cloud-assisted data publish/subscribe (Pub/Sub) service provides an asynchronous method for publishers and subscribers to non-interactively exchange encrypted messages. Besides performing conjunctive subscription policy, numerous data Pub/Sub systems have recently been proposed to provide dynamic access control enforced from the publisher side to the subscriber side. However, these solutions fail to consider the following properties: (i) bilateral access control for both publishers and subscribers; (ii) the anonymity of the publisher; (iii) high matching time cost between publication and subscription. Therefore, we present P/S-BiAC, a secure and boolean cloud-assisted data Pub/Sub system with attribute-based bilateral access control that achieves authenticity and anonymity of publishers. In particular, P/S-BiAC enables cloud-based brokers to use the subscriber's trapdoor to match published data with sub-linear time complexity. Technically, we introduce a "BiAC-and-Hidden" technique to refine publication tuples and trapdoor in classic searchable symmetric encryption solutions. Moreover, we implement P/S-BiAC and evaluate its practical performance based on Enron dataset in real cloud environment. To deal with a conjunctive subscription policy, P/S-BiAC runs $27.8\times $ faster for matching time cost (with $s$ -term=10) compared to state-of-the-art solutions, which demonstrates its feasibility in practical data Pub/Sub services with strong security properties.
引用
收藏
页码:5286 / 5301
页数:16
相关论文
共 50 条
  • [1] Efficient Data Access Control With Fine-Grained Data Protection in Cloud-Assisted IIoT
    Qi, Saiyu
    Lu, Youshui
    Wei, Wei
    Chen, Xiaofeng
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (04): : 2886 - 2899
  • [2] Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
    Xu, Shengmin
    Yang, Guomin
    Mu, Yi
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (08) : 2101 - 2113
  • [3] Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
    Yu, Shucheng
    Wang, Cong
    Ren, Kui
    Lou, Wenjing
    [J]. 2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [4] Secure and efficient fine-grained data access control scheme in cloud computing
    Yang, Changsong
    Ye, Jun
    [J]. JOURNAL OF HIGH SPEED NETWORKS, 2015, 21 (04) : 259 - 271
  • [5] Achieving fine-grained access control for secure data sharing on cloud servers
    Wang, Guojun
    Liu, Qin
    Wu, Jie
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2011, 23 (12): : 1443 - 1464
  • [6] Towards Secure Cloud Database with Fine-Grained Access Control
    Solomon, Michael G.
    Sunderam, Vaidy
    Xiong, Li
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 324 - 338
  • [7] Secure Fine-Grained Access Control of Mobile User Data through Untrusted Cloud
    Zhou, Kai
    Ren, Jian
    [J]. 2016 25TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN), 2016,
  • [8] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou Yousheng
    Chen Lujun
    [J]. JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (07) : 1856 - 1863
  • [9] DACSC: Dynamic and Fine-Grained Access Control for Secure Data Collaboration in Cloud Computing
    Huang, Qinlong
    Li, Nan
    Yang, Yixian
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [10] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou, Yousheng
    Chen, Lüjun
    [J]. Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2021, 43 (07): : 1856 - 1863