Secure Cloud-Assisted Data Pub/Sub Service With Fine-Grained Bilateral Access Control

被引:1
|
作者
Zhang, Kai [1 ]
Wang, Xiwen [1 ]
Ning, Jianting [2 ,3 ]
Gong, Junqing [4 ]
Huang, Xinyi [2 ,5 ]
机构
[1] Shanghai Univ Elect Power, Coll Comp Sci & Technol, Shanghai 201306, Peoples R China
[2] Fujian Normal Univ, Coll Comp & Cyber Secur, Key Lab Analyt Math & Applicat, Minist Educ, Fuzhou 350007, Peoples R China
[3] City Univ Macau, Fac Data Sci, Macau, Peoples R China
[4] East China Normal Univ, Software Engn Inst, Shanghai 200062, Peoples R China
[5] Hong Kong Univ Sci & Technol Guangzhou, Thrust Artificial Intelligence Informat Hub, Guangzhou 511453, Peoples R China
基金
中国国家自然科学基金;
关键词
Access control; Costs; Encryption; Time complexity; Data privacy; Privacy; Task analysis; Data publish/subscribe service; searchable encryption; matchmaking encryption; bilateral access control; SEARCHABLE SYMMETRIC-ENCRYPTION; PUBLISH/SUBSCRIBE SYSTEMS; INTERNET; SUPPORT;
D O I
10.1109/TIFS.2023.3303720
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Secure cloud-assisted data publish/subscribe (Pub/Sub) service provides an asynchronous method for publishers and subscribers to non-interactively exchange encrypted messages. Besides performing conjunctive subscription policy, numerous data Pub/Sub systems have recently been proposed to provide dynamic access control enforced from the publisher side to the subscriber side. However, these solutions fail to consider the following properties: (i) bilateral access control for both publishers and subscribers; (ii) the anonymity of the publisher; (iii) high matching time cost between publication and subscription. Therefore, we present P/S-BiAC, a secure and boolean cloud-assisted data Pub/Sub system with attribute-based bilateral access control that achieves authenticity and anonymity of publishers. In particular, P/S-BiAC enables cloud-based brokers to use the subscriber's trapdoor to match published data with sub-linear time complexity. Technically, we introduce a "BiAC-and-Hidden" technique to refine publication tuples and trapdoor in classic searchable symmetric encryption solutions. Moreover, we implement P/S-BiAC and evaluate its practical performance based on Enron dataset in real cloud environment. To deal with a conjunctive subscription policy, P/S-BiAC runs $27.8\times $ faster for matching time cost (with $s$ -term=10) compared to state-of-the-art solutions, which demonstrates its feasibility in practical data Pub/Sub services with strong security properties.
引用
收藏
页码:5286 / 5301
页数:16
相关论文
共 50 条
  • [41] Secure and fine-grained access control on e-healthcare records in mobile cloud computing
    Liu, Yi
    Zhang, Yinghui
    Ling, Jie
    Liu, Zhusong
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 78 : 1020 - 1026
  • [42] A Blockchain-based Secure Cloud Files Sharing Scheme with Fine-Grained Access Control
    Liu, Yuke
    Zhang, Junwei
    Gao, Qi
    [J]. 2018 INTERNATIONAL CONFERENCE ON NETWORKING AND NETWORK APPLICATIONS (NANA), 2018, : 277 - 283
  • [43] An Efficient Dynamic Fine Grained Access Control Scheme for Secure Data Access in Cloud Networks
    Chatterjee, Santanu
    Gupta, Amit Kumar
    Sudhakar, G. V.
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND COMMUNICATION TECHNOLOGIES, 2015,
  • [44] An efficient fine-grained data access control system with a bounded service number
    Liu, Xin
    Wang, Hao
    Zhang, Bo
    Zhang, Bin
    [J]. INFORMATION SCIENCES, 2022, 584 : 536 - 563
  • [45] Secure and Efficient Data Aggregation Scheme with Fine-Grained Access Control and Verifiability for CWBANs
    Fang, Xuefeng
    Gan, Qingqing
    Wang, Xiaoming
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (03): : 771 - 780
  • [46] Provably Secure Fine-Grained Data Access Control Over Multiple Cloud Servers in Mobile Cloud Computing Based Healthcare Applications
    Roy, Sandip
    Das, Ashok Kumar
    Chatterjee, Santanu
    Kumar, Neeraj
    Chattopadhyay, Samiran
    Rodrigues, Joel J. P. C.
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (01) : 457 - 468
  • [47] Secure semi-automated GDPR compliance service with restrictive fine-grained access control
    Eiza, Max Hashem
    Ta, Vinh Thong
    Shi, Qi
    Cao, Yue
    [J]. SECURITY AND PRIVACY, 2024,
  • [48] Fine-grained Access Control Scheme Based on Cloud Storage
    Niu, Xiaojie
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMPUTER NETWORK, ELECTRONIC AND AUTOMATION (ICCNEA), 2017, : 512 - 515
  • [49] Secure, Efficient, and Weighted Access Control for Cloud-Assisted Industrial IoT
    Li, Qi
    Zhang, Qianqian
    Huang, Haiping
    Zhang, Wei
    Chen, Wei
    Wang, Huaqun
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (18) : 16917 - 16927
  • [50] Light weight and fine-grained access mechanism for secure access to outsourced data*
    Jahan, Mosarrat
    Seneviratne, Suranga
    Roy, Partha Sarathi
    Sakurai, Kouichi
    Seneviratne, Aruna
    Jha, Sanjay
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (23):