Achieving Fine-Grained Access Control with Discretionary User Revocation over Cloud Data

被引:0
|
作者
Dong, Qiuxiang [1 ]
Huang, Dijiang [1 ]
Luo, Jim [2 ]
Kang, Myong [2 ]
机构
[1] Arizona State Univ, Tempe, AZ 85281 USA
[2] Naval Res Lab, Washington, DC 20375 USA
关键词
Cloud Storage; Access Control; Encryption; CP-ABE; Discretionary Revocation; IAM; Directory;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Cloud storage solutions have gained momentum in recent years. However, cloud servers can not be fully trusted. Data access control have becomes one of the main impediments for further adoption. One appealing approach is to incorporate the access control into encrypted data, thus removing the need to trust the cloud servers. Among existing cryptographic solutions, Ciphertext Policy Attribute-Based Encryption (CP-ABE) is well suited for fine-grained data access control in cloud storage. As promising as it is, user revocation is a cumbersome problem that impedes its wide application. To address this issue, we design an access control system called DUR-CP-ABE, which implements identity-based User Revocation in a data owner Discretionary way. In short, the proposed solution provides the following salient features. First, user revocation enforcement is based on the discretion of the data owner, thus providing more flexibility. Second, no private key updates are needed when user revocation occurs. Third, the proposed scheme allows for group revocation of affiliated users in a batch operation. To the best of our knowledge, DUR-CP-ABE is the first CP-ABE solution to provide affiliation-based batch revocation functionality, which fits naturally into organizations' Identity and Access Management (IAM) structure. The analysis shows that the proposed access control system is provably secure and efficient in terms of computation, communication and storage.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Achieving Revocable Fine-Grained Cryptographic Access Control over Cloud Data
    Yang, Yanjiang
    Ding, Xuhua
    Lu, Haibing
    Wan, Zhiguo
    Zhou, Jianying
    [J]. INFORMATION SECURITY (ISC 2013), 2015, 7807 : 293 - 308
  • [2] Fine-Grained Access Control with User Revocation in Smart Manufacturing
    Gomez-Marin, Ernesto
    Martintoni, Davide
    Senni, Valerio
    Castillo, Encarnacion
    Parrilla, Luis
    [J]. ELECTRONICS, 2023, 12 (13)
  • [3] Fine-grained access control of EHRs in cloud using CP-ABE with user revocation
    Ramu, Gandikota
    Reddy, B. Eswara
    Jayanthi, Appawala
    Prasad, L. V. Narasimha
    [J]. HEALTH AND TECHNOLOGY, 2019, 9 (04) : 487 - 496
  • [4] Fine-grained access control of EHRs in cloud using CP-ABE with user revocation
    Gandikota Ramu
    B. Eswara Reddy
    Appawala Jayanthi
    L. V. Narasimha Prasad
    [J]. Health and Technology, 2019, 9 : 487 - 496
  • [5] Fine Grained Decentralized Access Control With Provable Data Transmission and User Revocation in Cloud
    Kaushik, Shweta
    Gandhi, Charu
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2021, 15 (02) : 29 - 52
  • [6] Attribute-Based Fine-Grained Access Control with User Revocation
    Ye, Jun
    Zhang, Wujun
    Wu, Shu-lin
    Gao, Yuan-yuan
    Qiu, Jia-tao
    [J]. INFORMATION AND COMMUNICATION TECHNOLOGY, 2014, 8407 : 586 - 595
  • [7] Fine-grained Access Control and Revocation for Sharing Data on Clouds
    Tu, Shan-shan
    Niu, Shao-zhang
    Li, Hui
    Yun Xiao-ming
    Li, Meng-jiao
    [J]. 2012 IEEE 26TH INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS & PHD FORUM (IPDPSW), 2012, : 2146 - 2155
  • [8] Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
    Yu, Shucheng
    Wang, Cong
    Ren, Kui
    Lou, Wenjing
    [J]. 2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [9] Achieving fine-grained access control for secure data sharing on cloud servers
    Wang, Guojun
    Liu, Qin
    Wu, Jie
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2011, 23 (12): : 1443 - 1464
  • [10] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    [J]. The Journal of China Universities of Posts and Telecommunications, 2015, (02) : 38 - 43