TY - GEN
T1 - Secure and verifiable data access control scheme with policy update and computation outsourcing for edge computing
AU - Guan, Yue
AU - Guo, Songtao
AU - Li, Pan
AU - Yang, Yuanyuan
N1 - Publisher Copyright:
© 2020 IEEE.
PY - 2020/12
Y1 - 2020/12
N2 - Edge computing means that computing tasks are executed on edge devices closer to the data source. It can effectively improve system response speed and reduce the risk of user data leakage. However, current data access control schemes usually focus on cloud computing and rarely on edge computing. Although attribute-based encryption (ABE) scheme can realize flexible and reliable access control, computing cost is too high with the increase of access policy complexity. Therefore, combining computation outsourcing technology with dynamic policy updating technology, we propose a data access control scheme based on ciphertext-policy ABE (CP-ABE) for edge computing. We outsource part of storage service and part of decryption computing to edge nodes, effectively reducing the computing pressure of users. When data owner requires a new access policy, policy update key is generated timely and transmitted to cloud service provider, which is used to update the access policy, reducing the risk of bandwidth consumption and leakage of the ciphertext back and forth transmission. Finally, security analysis and experiment results verify the safety and effectiveness of our scheme.
AB - Edge computing means that computing tasks are executed on edge devices closer to the data source. It can effectively improve system response speed and reduce the risk of user data leakage. However, current data access control schemes usually focus on cloud computing and rarely on edge computing. Although attribute-based encryption (ABE) scheme can realize flexible and reliable access control, computing cost is too high with the increase of access policy complexity. Therefore, combining computation outsourcing technology with dynamic policy updating technology, we propose a data access control scheme based on ciphertext-policy ABE (CP-ABE) for edge computing. We outsource part of storage service and part of decryption computing to edge nodes, effectively reducing the computing pressure of users. When data owner requires a new access policy, policy update key is generated timely and transmitted to cloud service provider, which is used to update the access policy, reducing the risk of bandwidth consumption and leakage of the ciphertext back and forth transmission. Finally, security analysis and experiment results verify the safety and effectiveness of our scheme.
KW - CP-ABE
KW - Dynamic policy update
KW - Edge computing
KW - Outsourced decryption
UR - https://www.scopus.com/pages/publications/85102375516
U2 - 10.1109/ICPADS51040.2020.00060
DO - 10.1109/ICPADS51040.2020.00060
M3 - Conference contribution
AN - SCOPUS:85102375516
T3 - Proceedings of the International Conference on Parallel and Distributed Systems - ICPADS
SP - 398
EP - 405
BT - Proceedings - 2020 IEEE 26th International Conference on Parallel and Distributed Systems, ICPADS 2020
PB - IEEE Computer Society
T2 - 26th IEEE International Conference on Parallel and Distributed Systems, ICPADS 2020
Y2 - 2 December 2020 through 4 December 2020
ER -