{"title":"Key Update as a Service (KAAS): An Agent-Based Modeling for Cloud-Based Access Control","authors":"S. Fugkeaw, Hiroyuki Sato","doi":"10.1109/BigDataCongress.2016.67","DOIUrl":null,"url":null,"abstract":"Changes (add, update or revoke) of attributes in the attribute-based access control (ABAC) require the users whose keys containing the changed attributes need to update their keys. In the ABAC setting, attribute authority or data owner has to re-generate the keys and re-distribute the keys to affected users. This imposes the computation and communication cost as well as the administrative cost to handle the attribute change. In this paper, we propose a key update scheme to support attribute changes in ciphertext policy - attribute based encryption (CP-ABE) based access control. We introduce key update algorithm as a part of access control service that is specifically aimed at optimizing user key update processing cost in multi-authority cloud. To this end, we employ a multi-agent system (MAS) to perform the access control functions including user authentication, key update handling, and authorization. To support key update process, the agents will execute key update algorithm by updating all user's keys containing changed attributes on behalf of the attribute authority (AA). In addition, we provide the security proof of our key updating scheme in the general security model. Finally, the performance evaluation is provided to substantiate the efficiency of our proposed scheme.","PeriodicalId":407471,"journal":{"name":"2016 IEEE International Congress on Big Data (BigData Congress)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Congress on Big Data (BigData Congress)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BigDataCongress.2016.67","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Changes (add, update or revoke) of attributes in the attribute-based access control (ABAC) require the users whose keys containing the changed attributes need to update their keys. In the ABAC setting, attribute authority or data owner has to re-generate the keys and re-distribute the keys to affected users. This imposes the computation and communication cost as well as the administrative cost to handle the attribute change. In this paper, we propose a key update scheme to support attribute changes in ciphertext policy - attribute based encryption (CP-ABE) based access control. We introduce key update algorithm as a part of access control service that is specifically aimed at optimizing user key update processing cost in multi-authority cloud. To this end, we employ a multi-agent system (MAS) to perform the access control functions including user authentication, key update handling, and authorization. To support key update process, the agents will execute key update algorithm by updating all user's keys containing changed attributes on behalf of the attribute authority (AA). In addition, we provide the security proof of our key updating scheme in the general security model. Finally, the performance evaluation is provided to substantiate the efficiency of our proposed scheme.