Distributed and Secure Access Control in P2P Databases

Abstract : The intent of peer data management systems (PDMS) is to share as much data as possible. However, in many applications leveraging sensitive data, users demand adequate mechanisms to restrict the access to authorized parties. In this paper, we study a distributed access control model, where data items are stored, queried and authenticated in a totally decentralized fashion. Our contribution focuses on the design of a comprehensive framework for access control enforcement in PDMS sharing secure data, which blends policy rules defined in a declarative language with distributed key management schemes. The data owner peer decides which data to share and whom to share with by means of such policies, with the data encrypted accordingly. To defend against malicious attackers who can compromise the peers, the decryption keys are decomposed into pieces scattered amongst peers. We discuss the details of how to adapt distributed encryption schemes to PDMS to enforce robust and resilient access control, and demonstrate the efficiency and scalability of our approach by means of an extensive experimental study.
Type de document :
Communication dans un congrès
Sara Foresti; Sushil Jajodia. 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSEC), Jun 2010, Rome, Italy. Springer, Lecture Notes in Computer Science, LNCS-6166, pp.113-129, 2010, Data and Applications Security and Privacy XXIV. 〈10.1007/978-3-642-13739-6_8〉
Liste complète des métadonnées

Littérature citée [26 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01056665
Contributeur : Hal Ifip <>
Soumis le : mercredi 20 août 2014 - 13:40:26
Dernière modification le : mercredi 3 janvier 2018 - 17:12:02
Document(s) archivé(s) le : jeudi 27 novembre 2014 - 11:43:08

Fichier

_38.pdf
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Angela Bonifati, Ruilin Liu, Hui (wendy) Wang. Distributed and Secure Access Control in P2P Databases. Sara Foresti; Sushil Jajodia. 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSEC), Jun 2010, Rome, Italy. Springer, Lecture Notes in Computer Science, LNCS-6166, pp.113-129, 2010, Data and Applications Security and Privacy XXIV. 〈10.1007/978-3-642-13739-6_8〉. 〈hal-01056665〉

Partager

Métriques

Consultations de la notice

77

Téléchargements de fichiers

104