返回
A Parallel Secure Flow Control Framework for Private Data Sharing in Mobile Edge Cloud
DOI:10.1109/TPDS.2022.3200959.png)
摘要
En 中文
Nowadays, the rapid development of edge computing is accelerating the data sharing between cloud computing platforms and mobile users. These data often contain sensitive information, which faces severe leakage risks not only from the semi-trusted cloud servers but also from the malicious senders in the organizations. Fortunately, access control encryption (ACE) has been utilized to secure the data with access control policies, in which a sanitizer (e.g., the edge node) is employed to check all the communications between the sender and receiver, and drop illegal ciphertexts according to the access control policy. However, previous schemes have some limitations in mobile edge cloud, e.g., the sender's attributes are not strictly authenticated in the attribute-based access control policy, or the sanitization time is the bottleneck of fast data sharing. To this end, we introduce PSFlow, a parallel secure flow control framework for private data sharing in mobile edge cloud. First, we propose an attribute-based outsourced ACE (AOACE) scheme, which achieves secure fine-grained data read and write control, and reduces the computational cost of the sender and receiver with outsourced computations in edge nodes. Then, we propose a concrete construction of PSFlow from AOACE, and accelerate the sanitization process with parallel computing. Specifically, PSFlow parallelizes the sanitization operations with a multi-server model in each edge node, and optimizes the sanitization efficiency in each edge server by constructing a shared pool from the attribute universe. The experimental results show that PSFlow is more efficient and practical than previous schemes in mobile edge cloud.
Keyword:
Receivers
Encryption
Access control
Cloud computing
Servers
Mobile handsets
Costs
Access control encryption
data sharing
sanitization
mobile edge cloud
parallel computing
期刊
IF:
6
论文数:
5.2K
被引数:
1.1W
机构
引用论文
Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing云计算中基于属性的可验证和可加密的外包访问控制
Match in My Way: Fine-Grained Bilateral Access Control for Secure Cloud-Fog Computing以我的方式匹配: 安全云雾计算的细粒度双边访问控制
Expressive, Efficient, and Revocable Data Access Control for Multi-Authority Cloud Storage面向多权限云存储的可表达、高效、可撤销的数据访问控制
The Extended Cloud: Review and Analysis of Mobile Edge Computing and Fog From a Security and Resilience Perspective扩展云: 从安全和弹性角度回顾和分析移动边缘计算和雾

