A secure IoT cloud storage system with fine-grained access control and decryption key exposure resistance

被引:52
|
作者
Xu, Shengmin [1 ]
Yang, Guomin [2 ]
Mu, Yi [3 ]
Liu, Ximeng [1 ,4 ]
机构
[1] Singapore Management Univ, Sch Informat Syst, Singapore, Singapore
[2] Univ Wollongong, Sch Comp & Informat Technol, Inst Cybersecur & Cryptol, Wollongong, NSW, Australia
[3] Fujian Normal Univ, Fujian Prov Key Lab Network Secur & Cryptol, Fuzhou, Fujian, Peoples R China
[4] Fuzhou Univ, Coll Math & Comp Sci, Fuzhou, Fujian, Peoples R China
基金
中国国家自然科学基金;
关键词
IoT cloud; Attribute-based encryption; Revocation; Decryption key exposure; ATTRIBUTE-BASED ENCRYPTION; CREDENTIALS;
D O I
10.1016/j.future.2019.02.051
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Internet of Things (IoT) cloud provides a practical and scalable solution to accommodate the data management in large-scale IoT systems by migrating the data storage and management tasks to cloud service providers (CSPs). However, there also exist many data security and privacy issues that must be well addressed in order to allow the wide adoption of the approach. To protect data confidentiality, attribute-based cryptosystems have been proposed to provide fine-grained access control over encrypted data in loT cloud. Unfortunately, the existing attributed-based solutions are still insufficient in addressing some challenging security problems, especially when dealing with compromised or leaked user secret keys due to different reasons. In this paper, we present a practical attribute-based access control system for loT cloud by introducing an efficient revocable attribute-based encryption scheme that permits the data owner to efficiently manage the credentials of data users. Our proposed system can efficiently deal with both secret key revocation for corrupted users and accidental decryption key exposure for honest users. We analyze the security of our scheme with formal proofs, and demonstrate the high performance of the proposed system via experiments. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:284 / 294
页数:11
相关论文
共 50 条
  • [1] A Secure and Efficient Revocation Scheme for Fine-Grained Access Control in Cloud Storage
    Lv, Zhiquan
    Hong, Cheng
    Zhang, Min
    Feng, Dengguo
    [J]. 2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [2] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou Yousheng
    Chen Lujun
    [J]. JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (07) : 1856 - 1863
  • [3] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou, Yousheng
    Chen, Lüjun
    [J]. Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2021, 43 (07): : 1856 - 1863
  • [4] Towards Secure Cloud Database with Fine-Grained Access Control
    Solomon, Michael G.
    Sunderam, Vaidy
    Xiong, Li
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVIII, 2014, 8566 : 324 - 338
  • [5] Fine-grained Access Control Scheme Based on Cloud Storage
    Niu, Xiaojie
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMPUTER NETWORK, ELECTRONIC AND AUTOMATION (ICCNEA), 2017, : 512 - 515
  • [6] vFAC: Fine-Grained Access Control with Versatility for Cloud Storage
    Liu, Jingwei
    Tang, Huifang
    Li, Chaoya
    Sun, Rong
    Du, Xiaojiang
    Guizani, Mohsen
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [7] Secure IoT Data Outsourcing With Aggregate Statistics and Fine-Grained Access Control
    Liu, Ling
    Wang, He
    Zhang, Yuqing
    [J]. IEEE ACCESS, 2020, 8 : 95057 - 95067
  • [8] Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
    Yu, Shucheng
    Wang, Cong
    Ren, Kui
    Lou, Wenjing
    [J]. 2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [9] Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
    Xu, Shengmin
    Yang, Guomin
    Mu, Yi
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (08) : 2101 - 2113
  • [10] Secure and efficient fine-grained data access control scheme in cloud computing
    Yang, Changsong
    Ye, Jun
    [J]. JOURNAL OF HIGH SPEED NETWORKS, 2015, 21 (04) : 259 - 271