DocumentCode :
1808843
Title :
A Hybrid Enforcement Model for Group-centric Secure Information Sharing
Author :
Krishnan, Ram ; Sandhu, Ravi
Author_Institution :
George Mason Univ., Fairfax, VA, USA
Volume :
3
fYear :
2009
fDate :
29-31 Aug. 2009
Firstpage :
189
Lastpage :
194
Abstract :
Group-Centric Secure Information Sharing (g-SIS) is motivated by the need to dynamically share information amongst a set of authorized users for a specific purpose. Authorized group users may read and contribute new objects to the group. An important usability objective in g-SIS is to allow users to access group objects offline without having to contact a server every time an access is requested. Thus a fundamental requirement for g-SIS is that protection needs to extend to clients. Henceforth we assume that a Trusted Reference Monitor (TRM) is present on the client platforms that can enforce the group policies in a trustworthy manner. In this paper, we discuss three different approaches for realizing a scalable and high-assurance g-SIS. In a Micro-Distribution (MD) architecture, objects are individually encrypted for each group user. Thus the server shares a unique key with each user. In a Super-Distribution (SD) architecture, a single key is shared amongst all group users and thus group objects are uniformly encrypted. SD promotes ``protect once, access when authorized´´. We discuss the pros and cons of both MD and SD architecture and proposea novel split-key RSA based hybrid architecture. As we will see, this architecture incorporates the high-assurance aspect from MD and the usability and scalability advantages from SD approach respectively.
Keywords :
authorisation; public key cryptography; authorized user; encryption; group object access; group-centric secure information sharing; hybrid enforcement model; microdistribution architecture; split-key RSA based hybrid architecture; super-distribution architecture; trusted reference monitor; Aggregates; Computer networks; Costs; Data engineering; Data privacy; Educational institutions; Government; Protection; Telecommunication traffic; Wireless sensor networks; Architecture; Information Sharing; Split-key RSA; Super-distribution;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Science and Engineering, 2009. CSE '09. International Conference on
Conference_Location :
Vancouver, BC
Print_ISBN :
978-1-4244-5334-4
Electronic_ISBN :
978-0-7695-3823-5
Type :
conf
DOI :
10.1109/CSE.2009.397
Filename :
5283467
Link To Document :
بازگشت