AACS: A Secure Attribute Based Data Access Control for Cloud-aided Internet of Vehicles Using SGX

Wei,Saiyu Qi,Xu Yang,Wenjia Zhao,Jun Gu,Kashif Saleem,Yong Qi
DOI: https://doi.org/10.1109/tvt.2024.3398062
IF: 6.8
2024-01-01
IEEE Transactions on Vehicular Technology
Abstract:Internet of Vehicles (IoV) is a promising technology to equip transportation management systems with digitalized ability. The deployed IoV devices allow traffic participants to generate and analyze the traffic information such as driving status and road condition. They can further share the collected traffic data through the centralized cloud service to improve road operation efficiency, safety and reduce economic losses. Storing sensitive traffic data in an untrusted cloud server, however, raises the requirement of data access control to protect valuable business issues. Unfortunately, using pure cryptographic access control schemes for traffic data faces several limitations. In this paper, we first develop a pure cryptographic construction to enforce attribute-based access control (ABAC) model in untrusted cloud for IoV system based on ciphertext policy-attribute based encryption (CP-ABE) and explore three limitations of it. By studying ABAC in the context of CP-ABE, we can effectively lower-bound the costs that would be incurred when using more advanced and more expensive predicate encryption schemes. We then propose a new attribute based access control system (AACS) for cloud-aided IoV system to overcome the barriers of CP-ABE by using trusted hardware (Intel Software Guard Extensions (SGX)). AACS uses a secure data division framework to achieve a small Trusted Computing Base (TCB) and integrates SGX with several cryptographic protocols as well as optimization techniques. We comprehensively evaluate AACS to show the design advantages of it
What problem does this paper attempt to address?