首页> 外文会议>International Conference on Applied System Invention >Collaborative access control of cloud storage systems
【24h】

Collaborative access control of cloud storage systems

机译:云存储系统的协同访问控制

获取原文

摘要

Recently, cloud storage systems have become a popular means of data storage and sharing in a wide spectrum of application scenarios, especially in cloud computing systems. Although the present implementations of cloud storage systems such as Google Drive or HackMD offer the functionality to let multiple users edit the same documents at the same time, some issues on access controls might emerge. First, the existing access control policies allow the reads or writes of a file or directory if the corresponding access privileges are granted, in an all-or-nothing basis, and finer-grained controls are not realized. Then, the privileges to read or write a file are not completely orthogonal, thus the access controls for reads and writes should be asymmetric. In particular, a user that are granted to write a file cannot be always guaranteed to be able to read the same file, and vice versa. Last but not least, to avoid any intended or careless sabotage of any single user on critical files, multiple users must be able to collaboratively control the accesses to a file. Unfortunately, while the collaborative access control of files on cloud storage systems has been extensively studied, more sophisticated access control policies based on sets of users - referred to as manager groups in this work - still remain an unanswered problem, which motivates this work. In this work, we propose a collaborative access control strategy based on manager groups, which allow multiple groups to be connected in series or in parallel to further enhance the flexibility of access control of files on the cloud. In addition, we also considered several key implementation issues such as the performance of management, as well as the overheads for file encryption.
机译:最近,云存储系统已成为广泛应用场景中数据存储和共享的一种流行手段,尤其是在云计算系统中。尽管云存储系统(例如Google Drive或HackMD)的当前实现提供了允许多个用户同时编辑相同文档的功能,但是可能会出现一些有关访问控制的问题。首先,如果授予了相应的访问权限,那么现有访问控制策略将允许对文件或目录进行读写操作,而这种访问要么全有要么全无,并且无法实现更细粒度的控件。然后,读取或写入文件的权限并不完全正交,因此读取和写入的访问控制应该是不对称的。特别是,不能总是保证被授予写入文件权限的用户能够读取同一文件,反之亦然。最后但并非最不重要的一点是,为了避免任何单个用户对关键文件的蓄意破坏或粗心大意,多个用户必须能够协同控制对文件的访问。不幸的是,尽管对云存储系统上文件的协作访问控制进行了广泛的研究,但基于用户集的更复杂的访问控制策略(在本工作中称为管理者组)仍然是一个未解决的问题,这激发了这项工作。在这项工作中,我们提出了一种基于管理器组的协作式访问控制策略,该策略允许将多个组串联或并联连接,以进一步增强云上文件访问控制的灵活性。此外,我们还考虑了几个关键的实现问题,例如管理性能以及文件加密的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号