首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Cryptographically Enforced Role-Based Access Control for NoSQL Distributed Databases
【24h】

Cryptographically Enforced Role-Based Access Control for NoSQL Distributed Databases

机译:基于密码的NoSQL分布式数据库基于角色的访问控制

获取原文
获取外文期刊封面目录资料

摘要

The support for Role-Based Access Control (RBAC) using cryptography for NOSQL distributed databases is investigated. Cassandra is a NoSQL DBMS that efficiently supports very large databases, but provides rather simple security measures (an agent having physical access to a Cassandra cluster is usually assumed to have access to all data therein). Support for RBAC had been added almost as an afterthought, with the Node Coordinator having to mediate all requests to read and write data, in order to ensure that only the requests allowed by the Access Control Policy (ACP) are allowed through. In this paper, we propose a model and protocols for cryptographic enforcement of an ACP in a cassandra like system, which would ease the load on the Node Coordinator, thereby taking the bottleneck out of the existing security implementation. We allow any client to read the data from any storage node(s) - provided that only the clients whom the ACP grants access to a datum, would hold the encryption keys that enable these clients to decrypt the data.
机译:调查了对使用密码的NOSQL分布式数据库对基于角色的访问控制(RBAC)的支持。 Cassandra是NoSQL DBMS,可以有效地支持非常大的数据库,但是提供了相当简单的安全性措施(通常假定对Cassandra集群具有物理访问权的代理可以访问其中的所有数据)。几乎在事后才添加了对RBAC的支持,节点协调器必须调解所有读写数据的请求,以确保仅允许访问控制策略(ACP)允许的请求通过。在本文中,我们提出了一个模型和协议,用于在类似Cassandra的系统中对ACP进行加密实施,这将减轻节点协调器的负担,从而消除现有安全性实现的瓶颈。我们允许任何客户端从任何存储节点读取数据-前提是只有ACP授予访问数据权限的客户端才能持有使这些客户端能够解密数据的加密密钥。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号