首页> 外文OA文献 >Streamforce: outsourcing access control enforcement for stream data to the clouds
【2h】

Streamforce: outsourcing access control enforcement for stream data to the clouds

机译:streamforce:将流数据的访问控制执行外包给   云

摘要

As tremendous amount of data being generated everyday from human activity andfrom devices equipped with sensing capabilities, cloud computing emerges as ascalable and cost-effective platform to store and manage the data. Whilebenefits of cloud computing are numerous, security concerns arising when dataand computation are outsourced to a third party still hinder the completemovement to the cloud. In this paper, we focus on the problem of data privacyon the cloud, particularly on access controls over stream data. The nature ofstream data and the complexity of sharing data make access control a morechallenging issue than in traditional archival databases. We presentStreamforce - a system allowing data owners to securely outsource their data tothe cloud. The owner specifies fine-grained policies which are enforced by thecloud. The latter performs most of the heavy computations, while learningnothing about the data. To this end, we employ a number of encryption schemes,including deterministic encryption, proxy-based attribute based encryption andsliding-window encryption. In Streamforce, access control policies are modeledas secure continuous queries, which entails minimal changes to existing streamprocessing engines, and allows for easy expression of a wide-range of policies.In particular, Streamforce comes with a number of secure query operatorsincluding Map, Filter, Join and Aggregate. Finally, we implement Streamforceover an open source stream processing engine (Esper) and evaluate itsperformance on a cloud platform. The results demonstrate practical performancefor many real-world applications, and although the security overhead isvisible, Streamforce is highly scalable.
机译:随着每天从人类活动和配备传感功能的设备生成大量数据,云计算逐渐成为可扩展且经济高效的平台来存储和管理数据。尽管云计算的好处很多,但是当将数据和计算外包给第三方时出现的安全问题仍然阻碍了向云的完全迁移。在本文中,我们重点关注云上的数据隐私问题,尤其是对流数据的访问控制。与传统档案数据库相比,流数据的性质和共享数据的复杂性使访问控制成为一个更具挑战性的问题。我们提出了Streamforce-一种允许数据所有者将其数据安全外包给云的系统。所有者指定由cloud强制执行的细粒度策略。后者执行大部分繁重的计算,而对数据一无所知。为此,我们采用了多种加密方案,包括确定性加密,基于代理的基于属性的加密和滑动窗口加密。在Streamforce中,访问控制策略被建模为安全的连续查询,这需要对现有的流处理引擎进行最小的更改,并允许轻松表达各种策略。特别是,Streamforce附带了许多安全查询运算符,包括Map,Filter,加入并聚集。最后,我们在开源流处理引擎(Esper)上实现Streamforce,并在云平台上评估其性能。结果证明了许多实际应用程序的实用性能,尽管安全开销可见,但Streamforce具有高度可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号