RWAC: A Self-contained Read and Write Access Control Scheme for Group Collaboration

Jinmiao Wang, B. Lang, Ruijin Zhu
{"title":"RWAC: A Self-contained Read and Write Access Control Scheme for Group Collaboration","authors":"Jinmiao Wang, B. Lang, Ruijin Zhu","doi":"10.1109/ISCC.2018.8538611","DOIUrl":null,"url":null,"abstract":"With the development of the Internet and personal digital devices, self-organizing and open-pattern collaborations are becoming popular. In such environments, data are usually outsourced to third-party servers in the cloud, which are out of the control domain of data owners. Hence, traditional access control models, which are enforced relying on data storage servers, will face new security challenges. In this paper, we propose a self- contained read and write access control (RWAC) scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and attribute-based group signature (ABGS) mechanism. By adopting a two-step encryption strategy using CP-ABE and utilizing the write control policy as the signature policy in ABGS, RWAC ensures that fine-grained read and write access control can be enforced during decryption and signature generation without dependence on any third parties. To prevent privacy leakage from RWAC policies, we adopt a CP-ABE scheme with hidden policy. Then, we introduce the policy hiding method into ABGS and propose an ABGS scheme with hidden policy. Moreover, users can trace the edit history of each data object with the signature or a write list. The security analysis indicates that RWAC is able to enforce fine-grained read and write access controls for group collaborations while also ensuring data confidentiality and integrity.","PeriodicalId":233592,"journal":{"name":"2018 IEEE Symposium on Computers and Communications (ISCC)","volume":"81 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE Symposium on Computers and Communications (ISCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCC.2018.8538611","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

With the development of the Internet and personal digital devices, self-organizing and open-pattern collaborations are becoming popular. In such environments, data are usually outsourced to third-party servers in the cloud, which are out of the control domain of data owners. Hence, traditional access control models, which are enforced relying on data storage servers, will face new security challenges. In this paper, we propose a self- contained read and write access control (RWAC) scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and attribute-based group signature (ABGS) mechanism. By adopting a two-step encryption strategy using CP-ABE and utilizing the write control policy as the signature policy in ABGS, RWAC ensures that fine-grained read and write access control can be enforced during decryption and signature generation without dependence on any third parties. To prevent privacy leakage from RWAC policies, we adopt a CP-ABE scheme with hidden policy. Then, we introduce the policy hiding method into ABGS and propose an ABGS scheme with hidden policy. Moreover, users can trace the edit history of each data object with the signature or a write list. The security analysis indicates that RWAC is able to enforce fine-grained read and write access controls for group collaborations while also ensuring data confidentiality and integrity.
RWAC:一种组协作的自包含读写访问控制方案
随着互联网和个人数字设备的发展,自组织和开放模式的协作越来越受欢迎。在这种环境中,数据通常外包给云中的第三方服务器,这些服务器不在数据所有者的控制范围之内。因此,依赖于数据存储服务器的传统访问控制模型将面临新的安全挑战。本文提出了一种基于密文策略属性加密(CP-ABE)和基于属性的组签名(ABGS)机制的自包含读写访问控制(RWAC)方案。RWAC通过采用CP-ABE两步加密策略,并在ABGS中使用写控制策略作为签名策略,确保在解密和签名生成过程中可以实现细粒度的读写访问控制,而不依赖于任何第三方。为了防止RWAC策略的隐私泄露,我们采用了带有隐藏策略的CP-ABE方案。然后,将策略隐藏方法引入到ABGS中,提出了一种策略隐藏的ABGS方案。此外,用户还可以使用签名或写列表跟踪每个数据对象的编辑历史。安全性分析表明,RWAC能够在确保数据机密性和完整性的同时,为组协作实施细粒度的读写访问控制。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信