Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing

被引:745
|
作者
Yu, Shucheng [1 ]
Wang, Cong [2 ]
Ren, Kui [2 ]
Lou, Wenjing [1 ]
机构
[1] Worcester Polytech Inst, Dept ECE, Worcester, MA 01609 USA
[2] IIT, Dept ECE, Chicago, IL 60616 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/INFCOM.2010.5462174
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing is an emerging computing paradigm in which resources of the computing infrastructure are provided as services over the Internet. As promising as it is, this paradigm also brings forth many new challenges for data security and access control when users outsource sensitive data for sharing on cloud servers, which are not within the same trusted domain as data owners. To keep sensitive user data confidential against untrusted servers, existing solutions usually apply cryptographic methods by disclosing data decryption keys only to authorized users. However, in doing so, these solutions inevitably introduce a heavy computation overhead on the data owner for key distribution and data management when fine-grained data access control is desired, and thus do not scale well. The problem of simultaneously achieving fine-grainedness, scalability, and data confidentiality of access control actually still remains unresolved. This paper addresses this challenging open issue by, on one hand, defining and enforcing access policies based on data attributes, and, on the other hand, allowing the data owner to delegate most of the computation tasks involved in fine-grained data access control to untrusted cloud servers without disclosing the underlying data contents. We achieve this goal by exploiting and uniquely combining techniques of attribute-based encryption (ABE), proxy re-encryption, and lazy re-encryption. Our proposed scheme also has salient properties of user access privilege confidentiality and user secret key accountability. Extensive analysis shows that our proposed scheme is highly efficient and provably secure under existing security models.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Achieving fine-grained access control for secure data sharing on cloud servers
    Wang, Guojun
    Liu, Qin
    Wu, Jie
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2011, 23 (12): : 1443 - 1464
  • [2] Secure and efficient fine-grained data access control scheme in cloud computing
    Yang, Changsong
    Ye, Jun
    [J]. JOURNAL OF HIGH SPEED NETWORKS, 2015, 21 (04) : 259 - 271
  • [3] DACSC: Dynamic and Fine-Grained Access Control for Secure Data Collaboration in Cloud Computing
    Huang, Qinlong
    Li, Nan
    Yang, Yixian
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [4] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    [J]. The Journal of China Universities of Posts and Telecommunications, 2015, (02) : 38 - 43
  • [5] Method of secure, scalable, and fine-grained data access control with efficient revocation in untrusted cloud
    Song Lingwei
    Yu Fang
    Zhang Ru
    Niu Xinxin
    [J]. The Journal of China Universities of Posts and Telecommunications, 2015, 22 (02) - 43
  • [6] A fine-grained data access control algorithm in cloud computing
    Han, Dezhi
    Wu, Shuai
    Bi, Kun
    [J]. Huazhong Keji Daxue Xuebao (Ziran Kexue Ban)/Journal of Huazhong University of Science and Technology (Natural Science Edition), 2012, 40 (SUPPL.1): : 245 - 248
  • [7] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [8] Achieving Revocable Fine-Grained Cryptographic Access Control over Cloud Data
    Yang, Yanjiang
    Ding, Xuhua
    Lu, Haibing
    Wan, Zhiguo
    Zhou, Jianying
    [J]. INFORMATION SECURITY (ISC 2013), 2015, 7807 : 293 - 308
  • [9] Efficient Fine-Grained Access Control for Secure Personal Health Records in Cloud Computing
    He, Kai
    Weng, Jian
    Liu, Joseph K.
    Zhou, Wanlei
    Liu, Jia-Nan
    [J]. NETWORK AND SYSTEM SECURITY, (NSS 2016), 2016, 9955 : 65 - 79
  • [10] Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
    Xu, Shengmin
    Yang, Guomin
    Mu, Yi
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (08) : 2101 - 2113