Achieving Secure Role-Based Access Control on Encrypted Data in Cloud Storage

被引:134
|
作者
Zhou, Lan [1 ]
Varadharajan, Vijay [1 ]
Hitchens, Michael [1 ]
机构
[1] Macquarie Univ, Dept Comp, Adv Cyber Secur Res Ctr, N Ryde, NSW 2109, Australia
关键词
Role-based access control; data storage; role-based encryption; cloud computing; architecture; KEY MANAGEMENT; EFFICIENT;
D O I
10.1109/TIFS.2013.2286456
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid developments occurring in cloud computing and services, there has been a growing trend to use the cloud for large-scale data storage. This has raised the important security issue of how to control and prevent unauthorized access to data stored in the cloud. One well known access control model is the role-based access control (RBAC), which provides flexible controls and management by having two mappings, users to roles and roles to privileges on data objects. In this paper, we propose a role-based encryption (RBE) scheme that integrates the cryptographic techniques with RBAC. Our RBE scheme allows RBAC policies to be enforced for the encrypted data stored in public clouds. Based on the proposed scheme, we present a secure RBE-based hybrid cloud storage architecture that allows an organization to store data securely in a public cloud, while maintaining the sensitive information related to the organization's structure in a private cloud. We describe a practical implementation of the proposed RBE-based architecture and discuss the performance results. We demonstrate that users only need to keep a single key for decryption, and system operations are efficient regardless of the complexity of the role hierarchy and user membership in the system.
引用
收藏
页码:1947 / 1960
页数:14
相关论文
共 50 条
  • [1] Enforcing Role-Based Access Control for Secure Data Storage in the Cloud
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    COMPUTER JOURNAL, 2011, 54 (10): : 1675 - 1687
  • [2] Integrating Trust with Cryptographic Role-based Access Control for Secure Cloud Data Storage
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 560 - 569
  • [3] Trust Enhanced Cryptographic Role-Based Access Control for Secure Cloud Data Storage
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (11) : 2381 - 2395
  • [4] Trust-based Secure Cloud Data Storage with Cryptographic Role-based Access Control
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY (SECRYPT 2013), 2013, : 62 - 73
  • [5] A Trust Management Framework for Secure Cloud Data Storage Using Cryptographic Role-Based Access Control
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    E-BUSINESS AND TELECOMMUNICATIONS, ICETE 2013, 2014, 456 : 226 - 251
  • [6] REKS: Role-Based Encrypted Keyword Search With Enhanced Access Control for Outsourced Cloud Data
    Miao, Yinbin
    Li, Feng
    Jia, Xiaohua
    Wang, Huaxiong
    Liu, Ximeng
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3247 - 3261
  • [7] Role-based Access Control Using Ontology in Cloud Storage
    Sun, Hong
    Zhang, Xueqin
    Gu, Chunhua
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2014, 7 (03): : 1 - 12
  • [8] A Secure Role-Based Cloud Storage System For Encrypted Patient-Centric Health Records
    Zhou, Lan
    Varadharajan, Vijay
    Gopinath, K.
    COMPUTER JOURNAL, 2016, 59 (11): : 1593 - 1611
  • [9] A secure role-based cloud storage system for encrypted patient-centric health records
    Varadharajan, Vijay (vijay.varadharajan@mq.edu.au), 1600, Oxford University Press (59):
  • [10] A Secure and Efficient Role-Based Access Policy towards Cryptographic Cloud Storage
    Hong, Cheng
    Lv, Zhiquan
    Zhang, Min
    Feng, Dengguo
    WEB-AGE INFORMATION MANAGEMENT, 2011, 6897 : 264 - +