Journal on Communications ›› 2022, Vol. 43 ›› Issue (9): 27-41.doi: 10.11959/j.issn.1000-436x.2022165

• Papers • Previous Articles     Next Articles

HDFS-oriented cryptographic key resource control mechanism

Wei JIN1,2,3, Fenghua LI1,2, Mingjie YU1,4, Yunchuan GUO1,2, Ziyan ZHOU1,2, Liang FANG1   

  1. 1 Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    2 School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
    3 China Academy of Information and Communications Technology, Beijing 100191, China
    4 School of Cyber Security, University of Science and Technology of China, Hefei 230027, China
  • Revised:2022-06-07 Online:2022-09-25 Published:2022-09-01
  • Supported by:
    The National Natural Science Foundation of China(U1836203);The National Natural Science Foundation of China(61872441);The National Key Research and Development Program of China(2018YFB2100400);The Youth Innovation Promotion Association of Chinese Academy of Sciences(2021154)

Abstract:

The big data environment presents the characteristics of multi-user cross-network cross-access, multi-service collaborative computing, cross-service data flow, and complex management of massive files.The existing access control models and mechanisms are not fully applicable for big data scenarios.In response to the needs of fine-grained access control and multi-service strategy normalization for cryptographic data in the big data environment, starting from the scene elements and attributes of access control, the HDFS-oriented CKCM was proposed by mapping the cyberspace-oriented access control (CoAC) model.Subsequently, a fine-grained access control management model for HDFS was proposed, including management sub-models and management supporting models.The Z-notation was used to formally describe the management functions and management methods in the management model.Finally, the CKCM system was implemented based on XACML to realize fine-grained secure access control for managing file and secret keys in HDFS.

Key words: big data platform, cryptographic key management, resource control, cyberspace-oriented access control

CLC Number: 

No Suggested Reading articles found!