Title :
Attribute-based content distribution with hidden policy
Author :
Yu, Shucheng ; Ren, Kui ; Lou, Wenjing
Author_Institution :
Dept. of ECE, Worcester Polytech. Inst., Worcester, MA
Abstract :
Access control in content distribution networks (CDNs) is a long-standing problem and has attracted extensive research. Traditional centralized access control approaches, such as reference monitor based approach, do not suit for CDNs as such networks are of large scale and geographically distributed in nature. Current CDNs usually resort to cryptographic-based distributed approaches for better fulfilling the goal of access control. Hence, it is highly critical to design and adapt appropriate cryptographic primitives for such purpose. In this paper, we propose a novel distributed access control approach for CDNs by exploiting a new cryptographic primitive called Ciphertext Policy Attributed-Based Encryption (CP-ABE). Our approach provides flexible yet fine-grained access control (per file level) so that the contents are available only to the authorized users. We further consider the protection of user privacy and enhance the current design of CP-ABE so that not only the cAccess control in content distribution networks (CDNs) is a long-standing problem and has attracted extensive research. Traditional centralized access control approaches, such as reference monitor based approach, do not suit for CDNs as such networks are of large scale and geographically distributed in nature. Current CDNs usually resort to cryptographic-based distributed approaches for better fulfilling the goal of access control. Hence, it is highly critical to design and adapt appropriate cryptographic primitives for such purpose. In this paper, we propose a novel distributed access control approach for CDNs by exploiting a new cryptographic primitive called ciphertext policy attributed-based encryption (CP-ABE). Our approach provides flexible yet fine-grained access control (per file level) so that the contents are available only to the authorized users. We further consider the protection of user privacy and enhance the current design of CP-ABE so that not only the contents themselves but also th- - e access policies, which could lead to the revelation of sensitive user information, are well protected.ontents themselves but also the access policies, which could lead to the revelation of sensitive user information, are well protected.
Keywords :
authorisation; cryptography; data privacy; attribute-based content distribution networks; centralized access control approaches; ciphertext policy attributed-based encryption; cryptographic primitive; cryptographic-based distributed approaches; hidden policy; user privacy protection; Access control; Access protocols; Cryptography; Delay; Human resource management; Internet; Large-scale systems; Monitoring; Privacy; Protection;
Conference_Titel :
Secure Network Protocols, 2008. NPSec 2008. 4th Workshop on
Conference_Location :
Orlando, FL
Print_ISBN :
978-1-4244-2651-5
Electronic_ISBN :
978-1-4244-2652-2
DOI :
10.1109/NPSEC.2008.4664879