Exploiting Hierarchical Identity-Based Encryption for Access Control to Pervasive Computing Information

Abstract

Access control to sensitive information available in pervasive computing environments is challenging for multiple reasons: First, access control must support flexible access rights that include context-based constraints. Second, a client requesting access to sensitive information might not know which of its access rights are necessary in order to be granted access to the requested information. Third, pervasive computing environments consist of a multitude of information services, which makes simple management of access rights essential. Given this setting, we discuss the shortcomings of existing access control schemes that rely either on information services encrypting sensitive information before handing it over to clients or on clients presenting a proof of access to a service before being granted access. To address these shortcomings, we develop a solution based on hierarchical identity-based encryption. Namely, we present an encryption-based access control architecture that exploits hierarchical identity-based encryption in order to deal with multiple, hierarchical constraints on access rights. Furthermore, we introduce a proof-based access control architecture that employs hierarchical identity-based encryption in order to enable services to inform clients of the required proof of access in a covert way, without leaking information. We present an example implementation of our proposed schemes and discuss its performance.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Oct 01, 2004
Accession Number
ADA457869

Entities

People

  • Peter Steenkiste
  • Urs Hengartner

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Algorithms
  • Asymmetry
  • Computations
  • Computer Access Control
  • Computer Science
  • Computers
  • Cryptography
  • Denial Of Service Attack
  • Environment
  • Hardness
  • Hierarchies
  • Identification
  • Identities
  • Information Operations
  • Mobile Phones
  • Test And Evaluation
  • Ubiquitous Computing

Fields of Study

  • Computer science

Readers

  • Computer Networking
  • Cybersecurity.
  • Distributed Systems and Data Platform Development