SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and Analytics

被引:3
|
作者
Xue, Tao [1 ,2 ]
Wen, Yu [1 ]
Luo, Bo [3 ]
Li, Gang [4 ]
Li, Yingjiu [5 ]
Zhang, Boyang [1 ]
Zheng, Yang [1 ]
Hu, Yanfei [1 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100045, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 101408, Peoples R China
[3] Univ Kansas, Dept Elect Engn & Comp Sci, Lawrence, KS 66045 USA
[4] Deakin Univ, Ctr Cyber Secur Res & Innovat, Geelong, Vic 3217, Australia
[5] Univ Oregon, Dept Comp & Informat Sci, Eugene, OR 97403 USA
关键词
Sparks; Access control; Data analysis; Data models; Big Data; Optimization; Hospitals; Spark; big data; access control; data sharing; data protection; purpose; BIG-DATA; FLOW;
D O I
10.1109/TDSC.2022.3149544
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
With the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing purpose and data operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead.
引用
收藏
页码:1104 / 1123
页数:20
相关论文
共 50 条
  • [31] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    The Journal of China Universities of Posts and Telecommunications, 2015, (02) : 38 - 43
  • [32] Fine-grained Access Control Method for Blockchain Data Sharing based on Cloud Platform Big Data
    Qiu, Yu
    Sun, Biying
    Dang, Qian
    Du, Chunhui
    Li, Na
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (10) : 24 - 31
  • [33] DECENT: Secure and fine-grained data access control with policy updating for constrained IoT devices
    Qinlong Huang
    Licheng Wang
    Yixian Yang
    World Wide Web, 2018, 21 : 151 - 167
  • [34] DECENT: Secure and fine-grained data access control with policy updating for constrained IoT devices
    Huang, Qinlong
    Wang, Licheng
    Yang, Yixian
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2018, 21 (01): : 151 - 167
  • [35] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    The Journal of China Universities of Posts and Telecommunications, 2015, 22 (02) : 38 - 43
  • [36] A Fine-grained Multiparty Access Control Model for Photo Sharing in OSNs
    Lee, Chao
    Wang, Wei
    Guo, Yunchuan
    2016 IEEE FIRST INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC 2016), 2016, : 440 - 445
  • [37] A Secure and Lightweight Fine-Grained Data Sharing Scheme for Mobile Cloud Computing
    Li, Haifeng
    Lan, Caihui
    Fu, Xingbing
    Wang, Caifen
    Li, Fagen
    Guo, He
    SENSORS, 2020, 20 (17) : 1 - 17
  • [38] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [39] Fine-Grained Access Control for RDF Data on Mobile Devices
    Sacco, Owen
    Collina, Matteo
    Schiele, Gregor
    Corazza, Giovanni Emanuele
    Breslin, John G.
    Hauswirth, Manfred
    WEB INFORMATION SYSTEMS ENGINEERING - WISE 2013, PT I, 2013, 8180 : 478 - 487
  • [40] A Methodology for Fine-Grained Access Control in Exposing Biomedical Data
    Trifan, Alina
    van der Lei, Johan
    Diaz, Carlos
    Oliveira, Jose Luis
    BUILDING CONTINENTS OF KNOWLEDGE IN OCEANS OF DATA: THE FUTURE OF CO-CREATED EHEALTH, 2018, 247 : 561 - 565