首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >IBBE-SGX: Cryptographic Group Access Control Using Trusted Execution Environments
【24h】

IBBE-SGX: Cryptographic Group Access Control Using Trusted Execution Environments

机译:IBBE-SGX:使用可信执行环境的密码组访问控制

获取原文

摘要

While many cloud storage systems allow users to protect their data by making use of encryption, only few support collaborative editing on that data. A major challenge for enabling such collaboration is the need to enforce cryptographic access control policies in a secure and efficient manner. In this paper, we introduce IBBE-SGX, a new cryptographic access control extension that is efficient both in terms of computation and storage even when processing large and dynamic workloads of membership operations, while at the same time offering zero knowledge guarantees. IBBE-SGX builds upon Identity-Based Broadcasting Encryption (IBBE). We address IBBE's impracticality for cloud deployments by exploiting Intel Software Guard Extensions (SGX) to derive cuts in the computational complexity. Moreover, we propose a group partitioning mechanism such that the computational cost of membership update is bound to a fixed constant partition size rather than the size of the whole group. We have implemented and evaluated our new access control extension. Results highlight that IBBE-SGX performs membership changes 1.2 orders of magnitude faster than the traditional approach of Hybrid Encryption (HE), producing group metadata that are 6 orders of magnitude smaller than HE, while at the same time offering zero knowledge guarantees.
机译:尽管许多云存储系统允许用户通过使用加密来保护其数据,但只有极少数支持对数据进行协作编辑。实现这种协作的主要挑战是需要以安全有效的方式实施密码访问控制策略。在本文中,我们介绍了IBBE-SGX,这是一种新的密码访问控制扩展,即使在处理大型和动态成员资格操作工作负载时,它在计算和存储方面均非常有效,同时提供零知识保证。 IBBE-SGX建立在基于身份的广播加密(IBBE)的基础上。通过利用英特尔软件保护扩展(SGX)来减少计算复杂性,我们解决了IBBE在云部署中的不切实际之处。此外,我们提出了一种组划分机制,以便将成员资格更新的计算成本绑定到固定的恒定分区大小,而不是整个组的大小。我们已经实现并评估了我们的新访问控制扩展。结果表明,IBBE-SGX的成员资格更改比传统的混合加密(HE)方法快1.2个数量级,生成的组元数据比HE少6个数量级,同时提供零知识保证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号