• DocumentCode
    2907981
  • Title

    The Design and Implementation of a Sensitive Information System

  • Author

    Wang, Xiaoli ; Wu, Xianping ; Wang, Yiling ; Le, Phu Dung

  • Author_Institution
    Monash Univ., Melbourne, VIC, Australia
  • fYear
    2009
  • fDate
    24-26 Nov. 2009
  • Firstpage
    1174
  • Lastpage
    1179
  • Abstract
    Protecting sensitive information systems from security threats such as unauthorized access, information eavesdropping and information interfering, is significant. Most of the natural approaches employ strong authentication or cryptography systems to protect critical data. But those approaches do not stress on the potential amount of risks associated with sensitive information, especially the vulnerability from compromising of long term cryptographic keys and the lack of fine-grained access control for group sharing. Therefore, in this paper, we use dynamic key and group key theories to propose a new security architecture for sensitive information protection. The architecture categorizes sensitive information based on classified information. We implement the architecture by adopting elliptic curve cryptography (ECC) and dynamic key approaches to generate symmetric key to secure unicast and multicast communication among users. A formal analysis is provided to verify the security of the proposed work. It shows that the proposed system guarantees critical information data security and access control flexibility.
  • Keywords
    authorisation; cryptography; information systems; multicast communication; access control flexibility; dynamic key cryptography; elliptic curve cryptography; formal analysis; group key cryptography; information data security; information protection; multicast communication; security architecture; security threat; sensitive information system; unicast communication; Access control; Authentication; Data security; Elliptic curve cryptography; Information security; Information systems; Multicast communication; Protection; Stress; Unicast; Cryptography; Dynamic key; ECC and Group Diffie-Hellman (GDH); Hierarchical group key management (HGKM); Sensitive information system (SIS);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Sciences and Convergence Information Technology, 2009. ICCIT '09. Fourth International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-5244-6
  • Electronic_ISBN
    978-0-7695-3896-9
  • Type

    conf

  • DOI
    10.1109/ICCIT.2009.154
  • Filename
    5368895