高级检索

    数据空间中可比较属性的数据访问控制方案

    Data Access Control with Comparable Attribute for Dataspace

    • 摘要: 数据空间是实现数据有效共享和流通的重要基础设施. 但是,数据共享过程中面临的隐私泄露、数据窃取和非法滥用等问题给行业数据空间落地带来巨大挑战. 属性基加密能够确保共享数据的机密性和细粒度访问控制,但直接将其应用于数据空间还存在诸多问题. 首先,传统属性基加密方案在用户撤销时计算开销较大,无法满足数据空间中大量动态用户加入或退出的场景. 其次,许多行业数据空间需要根据用户属性比较和访问时间对其共享数据进行灵活的访问控制,并且能够对解密结果进行验证. 为解决上述问题,提出一种数据空间中基于可比较属性的数据访问控制方案,实现了灵活高效的用户撤销以确保前向安全性,能够根据访问时间和属性比较来对其访问行为进行灵活决策,并支持对解密过程的验证. 经过形式化安全分析,该方案在选择明文攻击下具有语义安全性. 大量的实验分析表明该方案适用于数据空间中数据的共享应用.

       

      Abstract: Dataspace is an important infrastructure for achieving effective data sharing and circulation. However, problems such as privacy leakage, data theft, and illegal abuse during the data sharing process bring big challenges to the implementation of industry dataspaces. Attribute-based Encryption (ABE) can ensure the confidentiality and fine-grained access control of shared data, but there are still many problems when directly applied to dataspaces. For example, traditional ABE have high computational overhead in user revocation, which cannot meet performance requirements if a lot of dynamic users joining or leaving the dataspace. Besides, many industry dataspaces need to exert flexible access control on shared data based on user attribute comparison and access time, and verify the decryption results. To overcome these problems, this paper proposes a data access control approach based on comparable attributes in dataspaces, which realizes flexible and efficient user revocation to ensure forward security. The approach can make flexible decisions on access behavior based on access time and attribute comparison, and also support verification of the decryption process. Through formal security analysis, the approach has semantic security under chosen plaintext attacks. In addition, a large number of experimental analyses show that the approach is suitable for actual data sharing applications in dataspaces.

       

    /

    返回文章
    返回