Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption

Cloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost...

Full description

Bibliographic Details
Main Authors: Haihe Ba, Huaizhe Zhou, Songzhu Mei, Huidong Qiao, Tie Hong, Zhiying Wang, Jiangchun Ren
Format: Article
Language:English
Published: MDPI AG 2018-09-01
Series:Symmetry
Subjects:
Online Access:http://www.mdpi.com/2073-8994/10/10/425
_version_ 1811306367458213888
author Haihe Ba
Huaizhe Zhou
Songzhu Mei
Huidong Qiao
Tie Hong
Zhiying Wang
Jiangchun Ren
author_facet Haihe Ba
Huaizhe Zhou
Songzhu Mei
Huidong Qiao
Tie Hong
Zhiying Wang
Jiangchun Ren
author_sort Haihe Ba
collection DOAJ
description Cloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost confidence in clouds to guarantee hosted cloud applications’ integrity. However, the state-of-the-art attestation schemes do not fit that multiple requesters raise their challenges simultaneously, thereby leading to larger performance overheads on the attester side. To address that, we propose an efficient and trustworthy concurrent attestation architecture under multi-requester scenarios, Astrape, to improve efficiency in the integrity and confidentiality protection aspects to generate an unforgeable and encrypted attestation report. Specifically, we propose two key techniques in this paper. The first one—aggregated attestation signature—reliably protects the attestation content from being compromised even in the presence of adversaries who have full control of the network, therefore successfully providing attestation integrity. The second one—delegation-based controlled report—introduces a third-party service to distribute the attestation report to requesters in order to save computation and communication overload on the attested party. The report is encrypted with an access policy by using attribute-based encryption and accessed by a limited number of qualified requesters, hence supporting attestation confidentiality. The experimental results show that Astrape can take no more than 0.4 s to generate an unforgeable and encrypted report for 1000 requesters and deliver a throughput speedup of approximately 30 × in comparison to the existing attestation systems.
first_indexed 2024-04-13T08:44:09Z
format Article
id doaj.art-4e156a8c20ba4201a741bb8d5f29fd15
institution Directory Open Access Journal
issn 2073-8994
language English
last_indexed 2024-04-13T08:44:09Z
publishDate 2018-09-01
publisher MDPI AG
record_format Article
series Symmetry
spelling doaj.art-4e156a8c20ba4201a741bb8d5f29fd152022-12-22T02:53:47ZengMDPI AGSymmetry2073-89942018-09-01101042510.3390/sym10100425sym10100425Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based EncryptionHaihe Ba0Huaizhe Zhou1Songzhu Mei2Huidong Qiao3Tie Hong4Zhiying Wang5Jiangchun Ren6College of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost confidence in clouds to guarantee hosted cloud applications’ integrity. However, the state-of-the-art attestation schemes do not fit that multiple requesters raise their challenges simultaneously, thereby leading to larger performance overheads on the attester side. To address that, we propose an efficient and trustworthy concurrent attestation architecture under multi-requester scenarios, Astrape, to improve efficiency in the integrity and confidentiality protection aspects to generate an unforgeable and encrypted attestation report. Specifically, we propose two key techniques in this paper. The first one—aggregated attestation signature—reliably protects the attestation content from being compromised even in the presence of adversaries who have full control of the network, therefore successfully providing attestation integrity. The second one—delegation-based controlled report—introduces a third-party service to distribute the attestation report to requesters in order to save computation and communication overload on the attested party. The report is encrypted with an access policy by using attribute-based encryption and accessed by a limited number of qualified requesters, hence supporting attestation confidentiality. The experimental results show that Astrape can take no more than 0.4 s to generate an unforgeable and encrypted report for 1000 requesters and deliver a throughput speedup of approximately 30 × in comparison to the existing attestation systems.http://www.mdpi.com/2073-8994/10/10/425concurrent attestationciphertext-policy attribute-based encryptioncloud computing
spellingShingle Haihe Ba
Huaizhe Zhou
Songzhu Mei
Huidong Qiao
Tie Hong
Zhiying Wang
Jiangchun Ren
Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
Symmetry
concurrent attestation
ciphertext-policy attribute-based encryption
cloud computing
title Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
title_full Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
title_fullStr Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
title_full_unstemmed Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
title_short Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
title_sort astrape an efficient concurrent cloud attestation with ciphertext policy attribute based encryption
topic concurrent attestation
ciphertext-policy attribute-based encryption
cloud computing
url http://www.mdpi.com/2073-8994/10/10/425
work_keys_str_mv AT haiheba astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT huaizhezhou astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT songzhumei astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT huidongqiao astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT tiehong astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT zhiyingwang astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption
AT jiangchunren astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption