Secure attribute-based systems

被引:147
作者
Pirretti, Matthew [1 ]
Traynor, Patrick [2 ]
McDaniel, Patrick [3 ]
Waters, Brent [4 ]
机构
[1] Motorola Labs, Schaumburg, IL 60196 USA
[2] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
[3] Penn State Univ, SIIS Lab, CSE, University Pk, PA 16802 USA
[4] Univ Texas Austin, Austin, TX 78712 USA
关键词
D O I
10.3233/JCS-2009-0383
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Attributes define, classify, or annotate the datum to which they are assigned. However, traditional attribute architectures and cryptosystems are ill-equipped to provide security in the face of diverse access requirements and environments. In this paper, we introduce a novel secure information management architecture based on emerging attribute-based encryption (ABE) primitives. A policy system that meets the needs of complex policies is defined and illustrated. Based on the needs of those policies, we propose cryptographic optimizations that vastly improve enforcement efficiency. We further explore the use of such policies in two proposed applications: a HIPAA compliant distributed file system and a social network. A performance analysis and characterization of ABE primitives demonstrates the ability to reduce cryptographic costs by as much as 98% over previously proposed constructions. Through this, we demonstrate that our attribute system is an efficient solution for securely managing information in large, loosely-coupled, distributed systems.
引用
收藏
页码:799 / 837
页数:39
相关论文
共 39 条
[1]  
Antenise G., 2007, P ISOC NETW DISTR SY
[2]  
Bellare Mihir, 1993, P ACM C COMP COMM SE
[3]  
Bethencourt J., 2007, P IEEE S SEC PRIV OA
[4]  
Blaze M., 1998, FINANCIAL CRYPTOGRAP
[5]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[6]  
Bowman M., 1994, P ISMM INT C INT INF
[7]  
Camenisch J., 2002, P ACM C COMP COMM SE
[8]  
Canetti R., 1998, STOC, P209
[9]  
Canetti R., 1999, P IEEE INFOCOM 99 NE
[10]  
Cocks Clifford, 2001, CRYPTOGRAPHY CODING, V2260, P360, DOI DOI 10.1007/3-540-45325-3