APECS: A Distributed Access Control Framework for Pervasive Edge Computing Services

被引:13
作者
Dougherty, Sean [1 ]
Tourani, Reza [1 ]
Panwar, Gaurav [2 ]
Vishwanathan, Roopa [2 ]
Misra, Satyajayant [2 ]
Srikanteswara, Srikathyayani [3 ]
机构
[1] St Louis Univ, St Louis, MO 63103 USA
[2] New Mexico State Univ, Las Cruces, NM 88003 USA
[3] Intel Labs, Portland, OR USA
来源
CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2021年
基金
美国国家科学基金会;
关键词
Distributed access control; authentication; authorization; attribute-based encryption; edge computing; SECURE;
D O I
10.1145/3460120.3484804
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Edge Computing is a new computing paradigm where applications operate at the network edge, providing low-latency services with augmented user and data privacy. A desirable goal for edge computing is pervasiveness, that is, enabling any capable and authorized entity at the edge to provide desired edge services-pervasive edge computing (PEC). However, efficient access control of users receiving services and edge servers handling user data, without sacrificing performance is a challenge. Current solutions, based on "always-on" authentication servers in the cloud, negate the latency benefits of services at the edge and also do not preserve user and data privacy. In this paper, we present APECS, an advanced access control framework for PEC, which allows legitimate users to utilize any available edge services without need for communication beyond the network edge. The APECS framework leverages multi-authority attribute-based encryption to create a federated authority, which delegates the authentication and authorization tasks to semi-trusted edge servers, thus eliminating the need for an "always-on" authentication server in the cloud. Additionally, APECS prevents access to encrypted content by unauthorized edge servers. We analyze and prove the security of APECS in the Universal Composability framework and provide experimental results on the GENI testbed to demonstrate the scalability and effectiveness of APECS.
引用
收藏
页码:1405 / 1420
页数:16
相关论文
共 33 条
  • [1] [Anonymous], 2017, The Zettabyte Era: Trends and Analysis
  • [2] [Anonymous], 2017, IEEE_Communications_Surveys__Tutorials
  • [3] GENI: A federated testbed for innovative network experiments
    Berman, Mark
    Chase, Jeffrey S.
    Landweber, Lawrence
    Nakao, Akihiro
    Ott, Max
    Raychaudhuri, Dipankar
    Ricci, Robert
    Seskar, Ivan
    [J]. COMPUTER NETWORKS, 2014, 61 : 5 - 23
  • [4] Universally composable security: A new paradigm for cryptographic protocols
    Canetti, R
    [J]. 42ND ANNUAL SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE, PROCEEDINGS, 2001, : 136 - 145
  • [5] Chan C, 2018, IEEE INT SYMP INFO, P1725, DOI 10.1109/ISIT.2018.8437930
  • [6] Chase M, 2009, CCS'09: PROCEEDINGS OF THE 16TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, P121
  • [7] Cisco, 2017, White Paper
  • [8] Using Smart Edge IoT Devices for Safer, Rapid Response With Industry IoT Control Operations
    Condry, Michael W.
    Nelson, Catherine Blackadar
    [J]. PROCEEDINGS OF THE IEEE, 2016, 104 (05) : 938 - 946
  • [9] Achieving Scalable Access Control Over Encrypted Data for Edge Computing Networks
    Cui, Hui
    Yi, Xun
    Nepal, Surya
    [J]. IEEE ACCESS, 2018, 6 : 30049 - 30059
  • [10] Cross-Domain based Data Sharing Scheme in Cooperative Edge Computing
    Fan, Kai
    Pan, Qiang
    Wang, Junxiong
    Liu, Tingting
    Li, Hui
    Yang, Yintang
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING (IEEE EDGE), 2018, : 87 - 92