Key Update as a Service (KAAS): An Agent-Based Modeling for Cloud-Based Access Control

S. Fugkeaw, Hiroyuki Sato
{"title":"Key Update as a Service (KAAS): An Agent-Based Modeling for Cloud-Based Access Control","authors":"S. Fugkeaw, Hiroyuki Sato","doi":"10.1109/BigDataCongress.2016.67","DOIUrl":null,"url":null,"abstract":"Changes (add, update or revoke) of attributes in the attribute-based access control (ABAC) require the users whose keys containing the changed attributes need to update their keys. In the ABAC setting, attribute authority or data owner has to re-generate the keys and re-distribute the keys to affected users. This imposes the computation and communication cost as well as the administrative cost to handle the attribute change. In this paper, we propose a key update scheme to support attribute changes in ciphertext policy - attribute based encryption (CP-ABE) based access control. We introduce key update algorithm as a part of access control service that is specifically aimed at optimizing user key update processing cost in multi-authority cloud. To this end, we employ a multi-agent system (MAS) to perform the access control functions including user authentication, key update handling, and authorization. To support key update process, the agents will execute key update algorithm by updating all user's keys containing changed attributes on behalf of the attribute authority (AA). In addition, we provide the security proof of our key updating scheme in the general security model. Finally, the performance evaluation is provided to substantiate the efficiency of our proposed scheme.","PeriodicalId":407471,"journal":{"name":"2016 IEEE International Congress on Big Data (BigData Congress)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Congress on Big Data (BigData Congress)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BigDataCongress.2016.67","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Changes (add, update or revoke) of attributes in the attribute-based access control (ABAC) require the users whose keys containing the changed attributes need to update their keys. In the ABAC setting, attribute authority or data owner has to re-generate the keys and re-distribute the keys to affected users. This imposes the computation and communication cost as well as the administrative cost to handle the attribute change. In this paper, we propose a key update scheme to support attribute changes in ciphertext policy - attribute based encryption (CP-ABE) based access control. We introduce key update algorithm as a part of access control service that is specifically aimed at optimizing user key update processing cost in multi-authority cloud. To this end, we employ a multi-agent system (MAS) to perform the access control functions including user authentication, key update handling, and authorization. To support key update process, the agents will execute key update algorithm by updating all user's keys containing changed attributes on behalf of the attribute authority (AA). In addition, we provide the security proof of our key updating scheme in the general security model. Finally, the performance evaluation is provided to substantiate the efficiency of our proposed scheme.
密钥更新即服务(KAAS):基于代理的基于云的访问控制建模
基于属性的访问控制(ABAC)中属性的更改(添加、更新或撤销)要求其密钥包含更改属性的用户需要更新其密钥。在ABAC设置中,属性授权机构或数据所有者必须重新生成密钥,并将密钥重新分发给受影响的用户。这增加了处理属性变化的计算和通信成本以及管理成本。本文提出了一种密钥更新方案,以支持基于密文策略属性加密(CP-ABE)的访问控制中的属性更改。我们引入密钥更新算法作为访问控制服务的一部分,专门针对多授权云中用户密钥更新处理成本的优化。为此,我们采用多代理系统(MAS)来执行访问控制功能,包括用户身份验证、密钥更新处理和授权。为了支持密钥更新过程,代理将执行密钥更新算法,代表属性机构(AA)更新包含已更改属性的所有用户密钥。此外,我们还提供了密钥更新方案在通用安全模型下的安全性证明。最后,通过性能评价验证了所提方案的有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信