Achieving Secure Role-Based Access Control on Encrypted Data in Cloud Storage

被引:134
|
作者
Zhou, Lan [1 ]
Varadharajan, Vijay [1 ]
Hitchens, Michael [1 ]
机构
[1] Macquarie Univ, Dept Comp, Adv Cyber Secur Res Ctr, N Ryde, NSW 2109, Australia
关键词
Role-based access control; data storage; role-based encryption; cloud computing; architecture; KEY MANAGEMENT; EFFICIENT;
D O I
10.1109/TIFS.2013.2286456
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid developments occurring in cloud computing and services, there has been a growing trend to use the cloud for large-scale data storage. This has raised the important security issue of how to control and prevent unauthorized access to data stored in the cloud. One well known access control model is the role-based access control (RBAC), which provides flexible controls and management by having two mappings, users to roles and roles to privileges on data objects. In this paper, we propose a role-based encryption (RBE) scheme that integrates the cryptographic techniques with RBAC. Our RBE scheme allows RBAC policies to be enforced for the encrypted data stored in public clouds. Based on the proposed scheme, we present a secure RBE-based hybrid cloud storage architecture that allows an organization to store data securely in a public cloud, while maintaining the sensitive information related to the organization's structure in a private cloud. We describe a practical implementation of the proposed RBE-based architecture and discuss the performance results. We demonstrate that users only need to keep a single key for decryption, and system operations are efficient regardless of the complexity of the role hierarchy and user membership in the system.
引用
收藏
页码:1947 / 1960
页数:14
相关论文
共 50 条
  • [21] Achieving Lightweight, Time-Specific and Secure Access Control in Cloud Storage
    Wang, Yanchao
    Li, Fenghua
    Niu, Ben
    Xie, Rongna
    2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [22] A Novel Role-based Access Control Model in Cloud Environments
    Jun Luo
    Hongjun Wang
    Xun Gong
    Tianrui Li
    International Journal of Computational Intelligence Systems, 2016, 9 : 1 - 9
  • [23] An Efficient Authentication System to Access Electric Vehicle Data in The Cloud Based on Identity Role-based Access Control
    Sudarsono, Amang
    Sudibyo, Rahardhita Widyatra
    Winarno, Idris
    Yuliana, Mike
    2024 INTERNATIONAL ELECTRONICS SYMPOSIUM, IES 2024, 2024, : 207 - 214
  • [24] A Novel Role-based Access Control Model in Cloud Environments
    Luo, Jun
    Wang, Hongjun
    Gong, Xun
    Li, Tianrui
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2016, 9 (01) : 1 - 9
  • [25] Attribute-Based Storage Supporting Secure Deduplication of Encrypted Data in Cloud
    Cui, Hui
    Deng, Robert H.
    Li, Yingjiu
    Wu, Guowei
    IEEE TRANSACTIONS ON BIG DATA, 2019, 5 (03) : 330 - 342
  • [26] Attribute-based cloud storage with secure provenance over encrypted data
    Cui, Hui
    Deng, Robert H.
    Li, Yingjiu
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 79 : 461 - 472
  • [27] Achieving Secure and Dynamic Range Queries Over Encrypted Cloud Data
    Yang, Wei
    Geng, Yangyang
    Li, Lu
    Xie, Xike
    Huang, Liusheng
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2022, 34 (01) : 107 - 121
  • [28] Role-Based Access Control in a Data Grid Using the Storage Resource Broker and Shibboleth
    Vineela Muppavarapu
    Soon M. Chung
    Journal of Grid Computing, 2009, 7 : 265 - 283
  • [29] Enhanced attribute based access control with secure deduplication for big data storage in cloud
    Premkamal, Praveen Kumar
    Pasupuleti, Syam Kumar
    Singh, Abhishek Kumar
    Alphonse, P. J. A.
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (01) : 102 - 120
  • [30] Role-Based Access Control in a Data Grid Using the Storage Resource Broker and Shibboleth
    Muppavarapu, Vineela
    Chung, Soon M.
    JOURNAL OF GRID COMPUTING, 2009, 7 (02) : 265 - 283