首页> 外文学位 >Secure, policy-based, multi-recipient data sharing.
【24h】

Secure, policy-based, multi-recipient data sharing.

机译:安全,基于策略的多收件人数据共享。

获取原文
获取原文并翻译 | 示例

摘要

In distributed systems users often need to share sensitive data with other users based on the latter's ability to satisfy various policies. In many cases the data owner may not even know the identities of the data recipients, but deems it crucial that they are legitimate; i.e., satisfy the policy. Enabling such data sharing over the Internet faces the challenge of (1) securely associating access policies with data and enforcing them, and (2) protecting data as it traverses untrusted proxies and intermediate repositories. Furthermore, it is desirable to achieve properties such as: (1) flexibility of access policies; (2) privacy of sensitive access policies; (3) minimal reliance on trusted third parties; and (4) efficiency of access policy enforcement. Often schemes enabling controlled data sharing need to trade one property for another. In this dissertation, we propose two complimentary policy-based data sharing schemes that achieve different subsets of the above desired properties.;In the first part of this dissertation, we focus on CiphertextPolicy Attribute-Based Encryption (CP-ABE) schemes that specify and enforce access policies cryptographically and eliminate trusted mediators. We motivate the need for flexible attribute organization within user keys for efficient support of many practical applications. We then propose Ciphertext-Policy Attribute-Set Based Encryption (CP-ASBE) which is the first CP-ABE scheme to (1) efficiently support naturally occurring compound attributes, (2) support multiple numerical assignments for a given attribute in a single key and (3) provide efficient key management. While the CP-ASBE scheme minimizes reliance on trusted mediators, it can support neither context-based policies nor policy privacy. In the second part of this dissertation, we propose Policy Based Encryption System (PBES), which employs mediated decryption and supports both context-based policies and policy privacy. Finally, we integrate the proposed schemes into practical applications (i.e., CP-ASBE scheme with Attribute-Based Messaging (ABM) and PBES scheme with a conditional data sharing application in the Power Grid) and demonstrate their usefulness in practice.
机译:在分布式系统中,用户经常需要根据其他用户满足各种策略的能力与其他用户共享敏感数据。在许多情况下,数据所有者甚至可能不知道数据接收者的身份,但认为它们是合法的至关重要;即满足政策。在Internet上实现这种数据共享面临着以下挑战:(1)将访问策略与数据安全地关联起来并执行它们;(2)遍历不受信任的代理和中间存储库时保护数据。此外,期望实现诸如以下的特性:(1)访问策略的灵活性; (2)敏感访问策略的隐私; (3)对信任的第三方的依赖最小; (4)实施访问策略的效率。通常,实现受控数据共享的方案需要将一种资产换成另一种资产。在本文中,我们提出了两种基于策略的互补数据共享方案,可以实现上述所需属性的不同子集。以密码方式实施访问策略并消除受信任的中介者。我们激发了对用户键内灵活的属性组织的需求,以有效地支持许多实际应用。然后,我们提出基于密文策略的基于属性集的加密(CP-ASBE),这是第一个CP-ABE方案,用于(1)有效地支持自然出现的复合属性,(2)在单个密钥中支持给定属性的多个数值分配(3)提供有效的密钥管理。尽管CP-ASBE方案最大程度地减少了对受信任中介的依赖,但它既不能支持基于上下文的策略,也不能支持策略隐私。在本文的第二部分中,我们提出了基于策略的加密系统(PBES),该系统采用调解解密,并支持基于上下文的策略和策略隐私。最后,我们将提出的方案整合到实际应用中(即具有基于属性的消息传递(ABM)的CP-ASBE方案和具有条件数据共享应用的PBES方案在电网中的应用),并在实践中证明了它们的有用性。

著录项

  • 作者

    Bobba, Rakesh Babu.;

  • 作者单位

    University of Maryland, College Park.;

  • 授予单位 University of Maryland, College Park.;
  • 学科 Electrical engineering.;Computer engineering.;Computer science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 145 p.
  • 总页数 145
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号