Privacy-preserving attribute-keyword based data publish-subscribe service on cloud platforms
نویسندگان
چکیده
Data publish-subscribe service is an effective approach to selectively share and selectively receive data. Towards the huge amount of data generated in our daily life, cloud systems, with economical but powerful storage and computing resources, are inevitably becoming the most appropriate platform for data publication and subscription. However, cloud server may also curious about both the published data and the interests of the subscribers. In this paper, we propose a privacy-preserving Attribute-Keyword based data Publish-Subscribe (AKPS) scheme for cloud platforms. Specifically, in order to protect the privacy of the published data against the cloud server and other none-subscribers, we employ the attributebased encryption with decryption outsourcing to encrypt the published data, such that the publishers can control the data access by themselves and the major decryption overhead can be shift from the subscribers’ devices to the cloud server. To protect the subscribers’ interests, we propose a new searchable encryption to enable the subscribers to selectively receive interested data. Different from existing symmetric searchable encryption methods, the AKPS can support multiple publishers and multiple subscribers, while none of two publishers/subscribers share the same secret keys. Moreover, the publishers cannot act as the subscribers, and vice versa. To avoid bypassing access/subscription policy checking procedure, the AKPS smartly ties both access policy and subscription policy by two secrets. One secret is used to bundle the ciphertext and the tags together, while the other secret is used to bundle the subscription trapdoor and the pre-decryption key together. The security proof and performance evaluation show that the proposed AKPS scheme is provable secure in random oracle model and efficient in practice. © 2016 Elsevier Inc. All rights reserved.
منابع مشابه
Privacy-Preserving Data Publish-Subscribe Service on Cloud-based Platforms
Data publish-subscribe service is an effective approach to share and filter data. Due to the huge volume and velocity of data generated daily, cloud systems are inevitably becoming the platform for data publication and subscription. However, the privacy becomes a challenging issue as the cloud server cannot be fully trusted by both data publishers and data subscribers. In this paper, we propose...
متن کاملAttribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems
Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...
متن کاملP3S: A Privacy Preserving Publish-Subscribe Middleware
This paper presents P3S, a publish-subscribe middleware designed to protect the privacy of subscriber interest and confidentiality of published content. P3S combines recent advances in cryptography, specifically Ciphertext Policy Attribute Based Encryption (CP-ABE) and Predicate Based Encryption (PBE) with an innovative architecture to achieve the desired level of privacy. An initial P3S protot...
متن کاملPrivacy-Preserving Filtering and Covering in Content-Based Publish Subscribe Systems
Content-Based Publish-Subscribe (CBPS) is an asynchronous messaging paradigm that supports a highly dynamic and many-to-many communication pattern based on the content of the messages themselves. In general, a CBPS system has three distinct parties Content Publishers , Content Brokers, and Subscribers working in a highly decoupled fashion. The ability to seamlessly scale on demand has made CBPS...
متن کاملRealizing IoT service’s policy privacy over publish/subscribe-based middleware
The publish/subscribe paradigm makes IoT service collaborations more scalable and flexible, due to the space, time and control decoupling of event producers and consumers. Thus, the paradigm can be used to establish large-scale IoT service communication infrastructures such as Supervisory Control and Data Acquisition systems. However, preserving IoT service's policy privacy is difficult in this...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Inf. Sci.
دوره 387 شماره
صفحات -
تاریخ انتشار 2017