Cargando…

Rainbow: reliable personally identifiable information retrieval across multi-cloud

Personally identifiable information (PII) refers to any information that links to an individual. Sharing PII is extremely useful in public affairs yet hard to implement due to the worries about privacy violations. Building a PII retrieval service over multi-cloud, which is a modern strategy to make...

Descripción completa

Detalles Bibliográficos
Autores principales: Song, Zishuai, Ma, Hui, Sun, Shuzhou, Xin, Yansen, Zhang, Rui
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Springer Nature Singapore 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10238253/
https://www.ncbi.nlm.nih.gov/pubmed/37304830
http://dx.doi.org/10.1186/s42400-023-00146-z
_version_ 1785053253194481664
author Song, Zishuai
Ma, Hui
Sun, Shuzhou
Xin, Yansen
Zhang, Rui
author_facet Song, Zishuai
Ma, Hui
Sun, Shuzhou
Xin, Yansen
Zhang, Rui
author_sort Song, Zishuai
collection PubMed
description Personally identifiable information (PII) refers to any information that links to an individual. Sharing PII is extremely useful in public affairs yet hard to implement due to the worries about privacy violations. Building a PII retrieval service over multi-cloud, which is a modern strategy to make services stable where multiple servers are deployed, seems to be a promising solution. However, three major technical challenges remain to be solved. The first is the privacy and access control of PII. In fact, each entry in PII can be shared to different users with different access rights. Hence, flexible and fine-grained access control is needed. Second, a reliable user revocation mechanism is required to ensure that users can be revoked efficiently, even if few cloud servers are compromised or collapse, to avoid data leakage. Third, verifying the correctness of received PII and locating a misbehaved server when wrong data are returned is crucial to guarantee user’s privacy, but challenging to realize. In this paper, we propose Rainbow, a secure and practical PII retrieval scheme to solve the above issues. In particular, we design an important cryptographic tool, called Reliable Outsourced Attribute Based Encryption (ROABE) which provides data privacy, flexible and fine-grained access control, reliable immediate user revocation and verification for multiple servers simultaneously, to support Rainbow. Moreover, we present how to build Rainbow with ROABE and several necessary cloud techniques in real world. To evaluate the performance, we deploy Rainbow on multiple mainstream clouds, namely, AWS, GCP and Microsoft Azure, and experiment in browsers on mobile phones and computers. Both theoretical analysis and experimental results indicate that Rainbow is secure and practical.
format Online
Article
Text
id pubmed-10238253
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher Springer Nature Singapore
record_format MEDLINE/PubMed
spelling pubmed-102382532023-06-06 Rainbow: reliable personally identifiable information retrieval across multi-cloud Song, Zishuai Ma, Hui Sun, Shuzhou Xin, Yansen Zhang, Rui Cybersecur (Singap) Research Personally identifiable information (PII) refers to any information that links to an individual. Sharing PII is extremely useful in public affairs yet hard to implement due to the worries about privacy violations. Building a PII retrieval service over multi-cloud, which is a modern strategy to make services stable where multiple servers are deployed, seems to be a promising solution. However, three major technical challenges remain to be solved. The first is the privacy and access control of PII. In fact, each entry in PII can be shared to different users with different access rights. Hence, flexible and fine-grained access control is needed. Second, a reliable user revocation mechanism is required to ensure that users can be revoked efficiently, even if few cloud servers are compromised or collapse, to avoid data leakage. Third, verifying the correctness of received PII and locating a misbehaved server when wrong data are returned is crucial to guarantee user’s privacy, but challenging to realize. In this paper, we propose Rainbow, a secure and practical PII retrieval scheme to solve the above issues. In particular, we design an important cryptographic tool, called Reliable Outsourced Attribute Based Encryption (ROABE) which provides data privacy, flexible and fine-grained access control, reliable immediate user revocation and verification for multiple servers simultaneously, to support Rainbow. Moreover, we present how to build Rainbow with ROABE and several necessary cloud techniques in real world. To evaluate the performance, we deploy Rainbow on multiple mainstream clouds, namely, AWS, GCP and Microsoft Azure, and experiment in browsers on mobile phones and computers. Both theoretical analysis and experimental results indicate that Rainbow is secure and practical. Springer Nature Singapore 2023-06-03 2023 /pmc/articles/PMC10238253/ /pubmed/37304830 http://dx.doi.org/10.1186/s42400-023-00146-z Text en © The Author(s) 2023 https://creativecommons.org/licenses/by/4.0/Open AccessThis article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article's Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article's Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/ (https://creativecommons.org/licenses/by/4.0/) .
spellingShingle Research
Song, Zishuai
Ma, Hui
Sun, Shuzhou
Xin, Yansen
Zhang, Rui
Rainbow: reliable personally identifiable information retrieval across multi-cloud
title Rainbow: reliable personally identifiable information retrieval across multi-cloud
title_full Rainbow: reliable personally identifiable information retrieval across multi-cloud
title_fullStr Rainbow: reliable personally identifiable information retrieval across multi-cloud
title_full_unstemmed Rainbow: reliable personally identifiable information retrieval across multi-cloud
title_short Rainbow: reliable personally identifiable information retrieval across multi-cloud
title_sort rainbow: reliable personally identifiable information retrieval across multi-cloud
topic Research
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10238253/
https://www.ncbi.nlm.nih.gov/pubmed/37304830
http://dx.doi.org/10.1186/s42400-023-00146-z
work_keys_str_mv AT songzishuai rainbowreliablepersonallyidentifiableinformationretrievalacrossmulticloud
AT mahui rainbowreliablepersonallyidentifiableinformationretrievalacrossmulticloud
AT sunshuzhou rainbowreliablepersonallyidentifiableinformationretrievalacrossmulticloud
AT xinyansen rainbowreliablepersonallyidentifiableinformationretrievalacrossmulticloud
AT zhangrui rainbowreliablepersonallyidentifiableinformationretrievalacrossmulticloud