4.6 Article

Match in My Way: Fine-Grained Bilateral Access Control for Secure Cloud-Fog Computing

期刊

出版社

IEEE COMPUTER SOC
DOI: 10.1109/TDSC.2020.3001557

关键词

Access control; Receivers; Cloud computing; Encryption; Privacy; Cloud computing; fog computing; bilateral access control; fine-grained access control

资金

  1. Singapore National Research Foundation [NRF2018NCR-NSOE004-0001]
  2. AXA Research Fund
  3. National Natural Science Foundation of China [61972094, 61822202, 61872089]
  4. Innovation Capability Support Program of Shaanxi [2020KJXX052]
  5. Shaanxi Special Support Program Youth Top-notch Talent Program
  6. Key Research and Development Program of Shaanxi [2019KW-053, 2020ZDLGY08-04]

向作者/读者索取更多资源

This article introduces a cloud-fog-device data sharing system based on matchmaking attribute-based encryption (MABE), which provides data confidentiality and data source identification simultaneously. The system offers secure fine-grained bilateral access control and performance optimization, outperforming related solutions in terms of functionality and performance.
Cloud-fog computing is a novel paradigm to extend the functionality of cloud computing to provide a variety of on-demand data services via the edge network. Many cryptographic tools have been introduced to preserve data confidentiality against the untrustworthy network and cloud servers. However, how to efficiently identify and retrieve useful data from a large number of ciphertexts without a costly decryption mechanism remains a challenging problem. In this article, we introduce a cloud-fog-device data sharing system (CFDS) with data confidentiality and data source identification simultaneously based on a new cryptographic primitive named matchmaking attribute-based encryption (MABE) by extending matchmaking encryption in CRYPTO'19. Our solution offers a secure fine-grained bilateral access control that includes (1) fine-grained sender access control, (2) fine-grained receiver access control, (3) sender privacy, and (4) performance optimization via outsourcing data source identification to fog nodes. We give the formal definition and security models of MABE, and present a concrete construction with formal security proofs. We also offer a detailed security analysis of our proposed CFDS against real-world security threats. The extensive comparison and experimental simulation demonstrate that, by immigrating heavy workload to fog nodes, our scheme has better functionalities and performances than the most related solutions.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据