首页> 外文会议>IEEE Computer Security Foundations Symposium >Policy Privacy in Cryptographic Access Control
【24h】

Policy Privacy in Cryptographic Access Control

机译:密码访问控制中的策略隐私

获取原文

摘要

Cryptographic access control offers selective access to encrypted data via a combination of key management and functionality-rich cryptographic schemes, such as attribute-based encryption. Using this approach, publicly available meta-data may inadvertently leak information on the access policy that is enforced by cryptography, which renders cryptographic access control unusable in settings where this information is highly sensitive. We begin to address this problem by presenting rigorous definitions for policy privacy in cryptographic access control. For concreteness we set our results in the model of Role-Based Access Control (RBAC), where we identify and formalize several different flavors of privacy, however, our framework should serve as inspiration for other models of access control. Based on our insights we propose a new system which significantly improves on the privacy properties of state-of-the-art constructions. Our design is based on a novel type of privacy-preserving attribute-based encryption, which we introduce and show how to instantiate. We present our results in the context of a cryptographic RBAC system by Ferrara et al. (CSF'13), which uses cryptography to control read access to files, while write access is still delegated to trusted monitors. We give an extension of the construction that permits cryptographic control over write access. Our construction assumes that key management uses out-of-band channels between the policy enforcer and the users but eliminates completely the need for monitoring read/write access to the data.
机译:密码访问控制通过密钥管理和功能丰富的密码方案(例如基于属性的加密)的组合,提供对加密数据的选择性访问。使用此方法,可公开获得的元数据可能会无意间泄漏有关由密码执行的访问策略的信息,这使得密码访问控制无法在该信息高度敏感的设置中使用。我们通过在密码访问控制中提出严格的策略隐私定义来解决此问题。具体而言,我们将结果设置在基于角色的访问控制(RBAC)模型中,在该模型中,我们确定并形式化了几种不同的隐私样式,但是,我们的框架应该为其他访问控制模型提供灵感。根据我们的见解,我们提出了一种新系统,该系统可以显着改善最新结构的隐私性。我们的设计基于一种新型的基于隐私保护的基于属性的加密,我们将介绍并演示如何实例化。我们在Ferrara等人的密码RBAC系统的背景下展示我们的结果。 (CSF'13),它使用加密技术来控制对文件的读取访问,而写入访问仍委派给受信任的监视器。我们对结构进行了扩展,允许对写访问进行密码控制。我们的构造假设密钥管理使用策略执行者和用户之间的带外通道,但完全不需要监视对数据的读/写访问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号