Fine-grained access control based on Trusted Execution Environment

被引:14
|
作者
Fan, Yongkai [1 ,2 ]
Liu, Shengle [1 ,2 ]
Tan, Gang [3 ]
Qiao, Fei [4 ]
机构
[1] China Univ Petr, Dept Comp Sci & Technol, Beijing, Peoples R China
[2] China Univ Petr, Beijing Key Lab Petr Data Min, Beijing, Peoples R China
[3] Penn State Univ, Dept Comp Sci & Engn, University Pk, PA 16802 USA
[4] Tsinghua Univ, Dept Elect Engn, Beijing, Peoples R China
关键词
Trusted Execution Environment; CPABE; Sensitive information; Fine-grained access control; QUERIES; PRIVACY;
D O I
10.1016/j.future.2018.05.062
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the wide adoption of mobile devices, it becomes increasingly a reality that mobile users use a variety of apps from various sources. Since the enforcement of strict privacy is difficult, the inappropriate access by malicious apps is a major concern for mobile users, and access control becomes a challenge. In order to prevent the leakage of sensitive information ( such as the contact lists, or private pictures) by inappropriate or illegal access, we propose a fine-grained access-control scheme based on Ciphertext-Policy Attribute-Based Encryption (CPABE) and Trusted Execution Environment (TEE), which can effectively protect data. In the scheme, CPABE is adopted in a novel way to solve the important security problems by supporting fine-grained access control during the access period and by supporting the critical operations running in the trusted execution environment. The scheme can be used to mitigate the sensitive information attacks and enhance confidentiality. Moreover, it can reduce the risk in the case of one single authority. Compared to the traditional access-control mechanisms, our experimental results indicate that the proposed scheme satisfies the security requirements, and is superior to other existing schemes. (C) 2018 Elsevier B.V. All rights reserved.
引用
收藏
页码:551 / 561
页数:11
相关论文
共 50 条
  • [1] Research on the Fine-Grained Access Control based -on RBAC on the trusted domain
    Wan Ai-Xia
    [J]. 2011 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION AND INDUSTRIAL APPLICATION (ICIA2011), VOL II, 2011, : 236 - 239
  • [2] Research on the Fine-Grained Access Control based-on RBAC on the trusted domain
    Wan Ai-Xia
    [J]. 2010 THE 3RD INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION (PACIIA2010), VOL VII, 2010, : 237 - 240
  • [3] A Fine-grained General Purpose Secure Storage Facility for Trusted Execution Environment
    Catuogno, Luigi
    Galdi, Clemente
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 588 - 595
  • [4] Fine-Grained Data Access Control for Collaborative Process Execution on Blockchain
    Marangone, Edoardo
    Di Ciccio, Claudio
    Weber, Ingo
    [J]. BUSINESS PROCESS MANAGEMENT: BLOCKCHAIN, ROBOTIC PROCESS AUTOMATION, AND CENTRAL AND EASTERN EUROPE FORUM, 2022, 459 : 51 - 67
  • [5] A Fine-Grained Access Control Scheme in Fog-IoT Based Environment
    Derki, Mohamed Saddek
    Taboudjemat-Nouali, Nadia
    Nouali, Omar
    [J]. ADVANCED INTELLIGENT SYSTEMS FOR SUSTAINABLE DEVELOPMENT (AI2SD'2020), VOL 2, 2022, 1418 : 465 - 474
  • [6] Fine-grained Access Control Model Based on RBAC
    Gao, Lei
    Pan, Shulin
    [J]. AUTOMATION EQUIPMENT AND SYSTEMS, PTS 1-4, 2012, 468-471 : 1667 - +
  • [7] THE RESEARCH OF SPREADSHEET BASED ON FINE-GRAINED ACCESS CONTROL
    Zheng Yanwei
    Feng Zhiquan
    [J]. FIFTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER THEORY AND ENGINEERING (ICACTE 2012), 2012, : 245 - 251
  • [8] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [9] Fine-grained and Efficient Access Control in E-health Environment
    Miao, Tiantian
    Shen, Jian
    Jin, Xin
    Lai, Jin-Feng
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (07): : 2169 - 2176
  • [10] IoT Access Control Model Based on Blockchain and Trusted Execution Environment
    Jiang, Weijin
    Li, En
    Zhou, Wenying
    Yang, Ying
    Luo, Tiantian
    [J]. PROCESSES, 2023, 11 (03)