Publication | Closed Access
Over-encryption: management of access control evolution on outsourced data
373
Citations
12
References
2007
Year
Secure ServiceEngineeringService SecurityInformation SecurityData-centric SecurityAccess ControlData ManagementData PrivacyCloud Computing SecurityComputer ScienceData SecurityCryptographyEncryptionData OutsourcingEncrypted StorageAccess Control EvolutionCloud ComputingSelective Authorization PoliciesAuthorization Policies
Data outsourcing is an emerging paradigm enabling users and organizations to leverage external services for resource distribution, but it faces a crucial problem of enforcing selective authorization policies and supporting dynamic policy updates. The paper proposes a novel solution for enforcing access control and managing its evolution. The solution uses selective encryption with two layers—an inner layer by the owner for initial protection and an outer layer by the server to reflect policy changes—alongside a model, algorithm, and analysis to manage these layers and mitigate information exposure risks. The dual‑layer encryption approach delivers an efficient and robust solution for access control enforcement and evolution management.
Data outsourcing is emerging today as a successful paradigm allowing users and organizations to exploit external services for the distribution of resources. A crucial problem to be addressed in this context concerns the enforcement of selective authorization policies and the support of policy updates in dynamic scenarios. In this paper, we present a novel solution to the enforcement of access control and the management of its evolution. Our proposal is based on the application of selective encryption as a means to enforce authorizations. Two layers of encryption are imposed on data: the inner layer is imposed by the owner for providing initial protection, the outer layer is imposed by the server to reflect policy modifications. The combination of the two layers provides an efficient and robust solution. The paper presents a model, an algorithm for the management of the two layers, and an analysis to identify and therefore counteract possible information exposure risks.
| Year | Citations | |
|---|---|---|
Page 1
Page 1