Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption
Cloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost...
Main Authors: | , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2018-09-01
|
Series: | Symmetry |
Subjects: | |
Online Access: | http://www.mdpi.com/2073-8994/10/10/425 |
_version_ | 1811306367458213888 |
---|---|
author | Haihe Ba Huaizhe Zhou Songzhu Mei Huidong Qiao Tie Hong Zhiying Wang Jiangchun Ren |
author_facet | Haihe Ba Huaizhe Zhou Songzhu Mei Huidong Qiao Tie Hong Zhiying Wang Jiangchun Ren |
author_sort | Haihe Ba |
collection | DOAJ |
description | Cloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost confidence in clouds to guarantee hosted cloud applications’ integrity. However, the state-of-the-art attestation schemes do not fit that multiple requesters raise their challenges simultaneously, thereby leading to larger performance overheads on the attester side. To address that, we propose an efficient and trustworthy concurrent attestation architecture under multi-requester scenarios, Astrape, to improve efficiency in the integrity and confidentiality protection aspects to generate an unforgeable and encrypted attestation report. Specifically, we propose two key techniques in this paper. The first one—aggregated attestation signature—reliably protects the attestation content from being compromised even in the presence of adversaries who have full control of the network, therefore successfully providing attestation integrity. The second one—delegation-based controlled report—introduces a third-party service to distribute the attestation report to requesters in order to save computation and communication overload on the attested party. The report is encrypted with an access policy by using attribute-based encryption and accessed by a limited number of qualified requesters, hence supporting attestation confidentiality. The experimental results show that Astrape can take no more than 0.4 s to generate an unforgeable and encrypted report for 1000 requesters and deliver a throughput speedup of approximately 30 × in comparison to the existing attestation systems. |
first_indexed | 2024-04-13T08:44:09Z |
format | Article |
id | doaj.art-4e156a8c20ba4201a741bb8d5f29fd15 |
institution | Directory Open Access Journal |
issn | 2073-8994 |
language | English |
last_indexed | 2024-04-13T08:44:09Z |
publishDate | 2018-09-01 |
publisher | MDPI AG |
record_format | Article |
series | Symmetry |
spelling | doaj.art-4e156a8c20ba4201a741bb8d5f29fd152022-12-22T02:53:47ZengMDPI AGSymmetry2073-89942018-09-01101042510.3390/sym10100425sym10100425Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based EncryptionHaihe Ba0Huaizhe Zhou1Songzhu Mei2Huidong Qiao3Tie Hong4Zhiying Wang5Jiangchun Ren6College of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCollege of Computer, National University of Defense Technology, Changsha 410073, ChinaCloud computing emerges as a change in the business paradigm that offers pay-as-you-go computing capability and brings enormous benefits, but there are numerous organizations showing hesitation for the adoption of cloud computing due to security concerns. Remote attestation has been proven to boost confidence in clouds to guarantee hosted cloud applications’ integrity. However, the state-of-the-art attestation schemes do not fit that multiple requesters raise their challenges simultaneously, thereby leading to larger performance overheads on the attester side. To address that, we propose an efficient and trustworthy concurrent attestation architecture under multi-requester scenarios, Astrape, to improve efficiency in the integrity and confidentiality protection aspects to generate an unforgeable and encrypted attestation report. Specifically, we propose two key techniques in this paper. The first one—aggregated attestation signature—reliably protects the attestation content from being compromised even in the presence of adversaries who have full control of the network, therefore successfully providing attestation integrity. The second one—delegation-based controlled report—introduces a third-party service to distribute the attestation report to requesters in order to save computation and communication overload on the attested party. The report is encrypted with an access policy by using attribute-based encryption and accessed by a limited number of qualified requesters, hence supporting attestation confidentiality. The experimental results show that Astrape can take no more than 0.4 s to generate an unforgeable and encrypted report for 1000 requesters and deliver a throughput speedup of approximately 30 × in comparison to the existing attestation systems.http://www.mdpi.com/2073-8994/10/10/425concurrent attestationciphertext-policy attribute-based encryptioncloud computing |
spellingShingle | Haihe Ba Huaizhe Zhou Songzhu Mei Huidong Qiao Tie Hong Zhiying Wang Jiangchun Ren Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption Symmetry concurrent attestation ciphertext-policy attribute-based encryption cloud computing |
title | Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption |
title_full | Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption |
title_fullStr | Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption |
title_full_unstemmed | Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption |
title_short | Astrape: An Efficient Concurrent Cloud Attestation with Ciphertext-Policy Attribute-Based Encryption |
title_sort | astrape an efficient concurrent cloud attestation with ciphertext policy attribute based encryption |
topic | concurrent attestation ciphertext-policy attribute-based encryption cloud computing |
url | http://www.mdpi.com/2073-8994/10/10/425 |
work_keys_str_mv | AT haiheba astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT huaizhezhou astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT songzhumei astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT huidongqiao astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT tiehong astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT zhiyingwang astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption AT jiangchunren astrapeanefficientconcurrentcloudattestationwithciphertextpolicyattributebasedencryption |