Cryptographic Enforcement of Access Control Policies in the Cloud: Implementation and Experimental Assessment

被引:0
作者
Berlato, Stefano [1 ,2 ]
Carbone, Roberto [2 ]
Ranise, Silvio [2 ,3 ]
机构
[1] Univ Genoa, DIBRIS, Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] Univ Trento, Dept Math, Trento, Italy
来源
SECRYPT 2021: PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2021年
基金
欧盟地平线“2020”;
关键词
Cryptographic Access Control; Experimental Assessment; Honest but Curious Cloud Service Provider; STORAGE;
D O I
10.5220/0010608003700381
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While organisations move their infrastructure to the cloud, honest but curious Cloud Service Providers (CSPs) threaten the confidentiality of cloud-hosted data. In this context, many researchers proposed Cryptographic Access Control (CAC) schemes to support data sharing among users while preventing CSPs from accessing sensitive data. However, the majority of these schemes focuses on high-level features only and cannot adapt to the multiple requirements arising in different scenarios. Moreover, (almost) no CAC scheme implementation is available for enforcement of authorisation policies in the cloud, and performance evaluation is often overlooked. To fill this gap, we propose the toolchain COERCIVE, short for CryptOgraphy killEd (the honest but) cuRious Cloud servIce proVidEr, which is composed of two tools: TradeOffBoard and CryptoAC. TradeOffBoard assists organisations in identifying the optimal CAC architecture for their scenario. CryptoAC enforces authorisation policies in the cloud by deploying the architecture selected with TradeOffBoard. In this paper, we describe the implementation of CryptoAC and conduct a thorough performance evaluation to demonstrate its scalability and efficiency with synthetic benchmarks.
引用
收藏
页码:370 / 381
页数:12
相关论文
共 41 条
[31]   Data access control method for multimedia content data sharing and security based on XMDR-DAI in mobile cloud storage [J].
Jung, Kye-Dong ;
Moon, Seok-Jae ;
Kim, Jin-Mook .
MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (19) :19983-19999
[32]   Experimental Investigation and Numerical Modeling of Room Temperature Control in Buildings by the Implementation of Phase Change Material in the Roof [J].
Beemkumar, N. ;
Yuvarajan, D. ;
Arulprakasajothi, M. ;
Ganesan, S. ;
Elangovan, K. ;
Senthilkumar, G. .
JOURNAL OF SOLAR ENERGY ENGINEERING-TRANSACTIONS OF THE ASME, 2020, 142 (01)
[33]   Improvement of Quality in Publication of Experimental Thermophysical Property Data: Challenges, Assessment Tools, Global Implementation, and Online Support [J].
Chirico, Robert D. ;
Frenkel, Michael ;
Magee, Joseph W. ;
Diky, Vladimir ;
Muzny, Chris D. ;
Kazakov, Andrei F. ;
Kroenlein, Kenneth ;
Abdulagatov, Ilmutdin ;
Hardin, Gary R. ;
Acree, William E., Jr. ;
Brenneke, Joan F. ;
Brown, Paul L. ;
Cummings, Peter T. ;
de Loos, Theo W. ;
Friend, Daniel G. ;
Goodwin, Anthony R. H. ;
Hansen, Lee D. ;
Haynes, William M. ;
Koga, Nobuyoshi ;
Mandelis, Andreas ;
Marsh, Kenneth N. ;
Mathias, Paul M. ;
McCabe, Clare ;
O'Connell, John P. ;
Padua, Agilio ;
Rives, Vicente ;
Schick, Christoph ;
Trusler, J. P. Martin ;
Vyazovkin, Sergey ;
Weir, Ron D. ;
Wu, Jiangtao .
JOURNAL OF CHEMICAL AND ENGINEERING DATA, 2013, 58 (10) :2699-2716
[34]   RETRACTED: On the Design of Secured and Reliable Dynamic Access Control Scheme of Patient E-Healthcare Records in Cloud Environment (Retracted Article) [J].
Zala, Kirtirajsinh ;
Thakkar, Hiren Kumar ;
Jadeja, Rajendrasinh ;
Dholakia, Neel H. ;
Kotecha, Ketan ;
Jain, Deepak Kumar ;
Shukla, Madhu .
COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022
[35]   PMTER-ABE: a practical multi-authority CP-ABE with traceability, revocation and outsourcing decryption for secure access control in cloud systems [J].
Sethi, Kamalakanta ;
Pradhan, Ankit ;
Bera, Padmalochan .
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2021, 24 (02) :1525-1550
[36]   SeGoAC: A tree-based model for self-defined, proxy-enabled and group-oriented access control in mobile cloud computing [J].
Ren, Wei ;
Liv, Ran ;
Lei, Min ;
Choo, Kim-Kwang Raymond .
COMPUTER STANDARDS & INTERFACES, 2017, 54 :29-35
[37]   PCS-ABE (t, n): a secure threshold multi authority CP-ABE scheme based efficient access control systems for cloud environment [J].
Ramesh, Dharavath ;
Mishra, Rahul ;
Trivedi, Munesh Chandra .
JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2021, 12 (10) :9303-9322
[38]   Experimental assessment of integral-type terminal sliding mode control designed for a single-phase grid-interlinked PV system [J].
Chigane, Khalid ;
Ouassaid, Mohammed .
CONTROL ENGINEERING PRACTICE, 2024, 147
[39]   Experimental assessment of combined sliding mode & moment-based control (SM2C) for arrays of wave energy conversion systems [J].
Faedo, Nicolas ;
Mosquera, Facundo D. ;
Pasta, Edoardo ;
Papini, Guglielmo ;
Pena-Sanchez, Yerai ;
Evangelista, Carolina A. ;
Ferri, Francesco ;
Ringwood, John V. ;
Puleston, Paul .
CONTROL ENGINEERING PRACTICE, 2024, 144
[40]   A novel adaptive FOCV algorithm with robust IMRAC control for sustainable and high-efficiency MPPT in standalone PV systems: experimental validation and performance assessment [J].
Belghiti, Hamid ;
Kandoussi, Khalid ;
Harrison, Ambe ;
Moustaine, Fatima Zahra ;
El Otmani, Rabie ;
Sadek, El Mostafa ;
Bajaj, Mohit ;
Mohammadi, Shir Ahmad Dost .
SCIENTIFIC REPORTS, 2024, 14 (01)