计算机科学
访问控制
云计算
计算机安全
共谋
秘密分享
云存储
万维网
密码学
操作系统
业务
产业组织
作者
Hubert Ritzdorf,Claudio Soriente,Ghassan Karame,Srdjan Marinovic,Damian Gruber,Srđjan Čapkun
标识
DOI:10.1109/tifs.2018.2837648
摘要
Cloud storage platforms promise a convenient way for users to share files and engage in collaborations, yet they require all files to have a single owner who unilaterally makes access control decisions. Existing clouds are, thus, agnostic to the notion of shared ownership. This can be a significant limitation in much collaboration because, for example, one owner can delete files and revoke access without consulting the other collaborators. In this paper, we first formally define a notion of shared ownership within a file access control model. We then propose two possible instantiations of our proposed shared ownership model. Our first solution, called Commune, relies on secure file dispersal and collusion-resistant secret sharing to ensure that all access grants in the cloud require the support of an agreed threshold of owners. As such, Commune can be used in existing clouds without modifications to the platforms. Our second solution, dubbed Comrade, leverages the blockchain technology in order to reach consensus on access control decision. Unlike Commune, Comrade requires that the cloud is able to translate access control decisions that reach consensus in the blockchain into storage access control rules, thus requiring minor modifications to existing clouds. We analyze the security of our proposals and compare/evaluate their performance through implementations using Amazon S3.
科研通智能强力驱动
Strongly Powered by AbleSci AI