撤销
计算机科学
代理重新加密
加密
访问控制
代理(统计)
计算机安全
代理服务器
基于属性的加密
密码学
建筑
服务器
公钥密码术
计算机网络
操作系统
艺术
机器学习
视觉艺术
架空(工程)
作者
Sonia Jahid,Nikita Borisov
出处
期刊:Cornell University - arXiv
日期:2012-08-23
被引量:19
摘要
Access control to data in traditional enterprises is typically enforced through reference monitors. However, as more and more enterprise data is outsourced, trusting third party storage servers is getting challenging. As a result, cryptography, specifically Attribute-based encryption (ABE) is getting popular for its expressiveness. The challenge of ABE is revocation.
To address this challenge, we propose PIRATTE, an architecture that supports fine-grained access control policies and dynamic group membership. PIRATTE is built using attribute-based encryption; a key and novel feature of our architecture, however, is that it is possible to remove access from a user without issuing new keys to other users or re-encrypting existing ciphertexts. We achieve this by introducing a proxy that participates in the decryption process and enforces revocation constraints. The proxy is minimally trusted and cannot decrypt ciphertexts or provide access to previously revoked users. We describe the PIRATTE construction and provide a security analysis along with performance evaluation.We also describe an architecture for online social network that can use PIRATTE, and prototype application of PIRATTE on Facebook.
科研通智能强力驱动
Strongly Powered by AbleSci AI