Domain-Specific Fine-Grained Access Control for Cloud-Edge Collaborative IoT

Meiyan Xiao, Qiong Huang, Wenya Chen, Chuan Lyu, Willy Susilo · IEEE Transactions on Information Forensics and Security · 2024

The cloud-edge collaborative data sharing supporting data confidentiality can be realized by adopting outsourced Attribute-Based Encryption (ABE) schemes. Yet, most existing schemes in such kind of scenarios are facing challenges such as vulnerable terminal devices that are easy to be attacked, lack of flexible authorization management methods for a large number of devices, and lack methods to securely specify on-demand data sharing domains. In this paper, we propose a Domain-specific On-demand Access Control scheme with fully Independent Revocation (DOACIR), which not only realizes a three-layer on-demand data sharing framework for cloud-edge collaborative IoT environments but also allows data uploader to restrict the data sharing domain through a succinct way. The attribute authority and multiple edge servers perform data access authorization collaboratively to improve the data sharing efficiency as well as avoid the key-abuse problem and key-leakage problem. Fully independent user revocation is also realized in DOACIR to flexibly manage terminal devices in IoT. Further, we improve the scheme to support cross-domain data sharing, namely Cross-Domain DOACIR (CD-DOACIR), by improving the encryption phase allowing data uploader to specify any number of sharing domains while the size of ciphertext remains constant. We provide the security proofs of DOACIR and CD-DOACIR, and the experiment results demonstrate the effectiveness and efficiency of our solutions in cloud-edge collaborative on-demand data sharing.

Read the paper · More papers on PaperTik