HASBE: A Hierarchical Attribute-Based Solution for Flexible and Scalable Access Control in Cloud Computing

被引:310
|
作者
Wan, Zhiguo [1 ,2 ]
Liu, Jun'e [1 ,2 ]
Deng, Robert H. [3 ]
机构
[1] Tsinghua Univ, Minist Educ, Tsinghua Natl Lab Informat Sci & Technol, Key Lab Informat Syst Secur, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Sch Software, Beijing 100084, Peoples R China
[3] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
基金
中国国家自然科学基金;
关键词
Access control; cloud computing; data security;
D O I
10.1109/TIFS.2011.2172209
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing has emerged as one of the most influential paradigms in the IT industry in recent years. Since this new computing technology requires users to entrust their valuable data to cloud providers, there have been increasing security and privacy concerns on outsourced data. Several schemes employing attribute-based encryption (ABE) have been proposed for access control of outsourced data in cloud computing; however, most of them suffer from inflexibility in implementing complex access control policies. In order to realize scalable, flexible, and fine-grained access control of outsourced data in cloud computing, in this paper, we propose hierarchical attribute-set-based encryption (HASBE) by extending ciphertext-policy attribute-set-based encryption (ASBE) with a hierarchical structure of users. The proposed scheme not only achieves scalability due to its hierarchical structure, but also inherits flexibility and fine-grained access control in supporting compound attributes of ASBE. In addition, HASBE employs multiple value assignments for access expiration time to deal with user revocation more efficiently than existing schemes. We formally prove the security of HASBE based on security of the ciphertext-policy attribute-based encryption (CP-ABE) scheme by Bethencourt et al. and analyze its performance and computational complexity. We implement our scheme and show that it is both efficient and flexible in dealing with access control for outsourced data in cloud computing with comprehensive experiments.
引用
收藏
页码:743 / 754
页数:12
相关论文
共 50 条
  • [21] Attribute-Based Hierarchical Access Control With Extendable Policy
    Xiao, Meiyan
    Li, Hongbo
    Huang, Qiong
    Yu, Shui
    Susilo, Willy
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1868 - 1883
  • [22] Attribute-based data access control in mobile cloud computing: Taxonomy and open issues
    Sookhak, Mehdi
    Yu, F. Richard
    Khan, Muhammad Khurram
    Xiang, Yang
    Buyya, Rajkumar
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2017, 72 : 273 - 287
  • [23] Extended File Hierarchy Access Control Scheme with Attribute-Based Encryption in Cloud Computing
    Li, Jiguo
    Chen, Ningyu
    Zhang, Yichen
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2021, 9 (02) : 983 - 993
  • [24] Anonymous attribute-based proxy re-encryption for access control in cloud computing
    Zhang, Yinghui
    Li, Jin
    Chen, Xiaofeng
    Li, Hui
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (14) : 2397 - 2411
  • [25] Comments on "Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing"
    Xiong, Hu
    Sun, Jianfei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (04) : 461 - 462
  • [26] Quality Based Solution for Adaptable and Scalable Access Control in Cloud Computing
    Harika, A. Varalakshmi
    Haleema, P. K.
    Subalakshmi, R. Jaya
    Iyengar, N. Ch. S. N.
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2014, 7 (06): : 137 - 148
  • [27] Attribute-Based Keyword Search over Hierarchical Data in Cloud Computing
    Miao, Yinbin
    Ma, Jianfeng
    Liu, Ximeng
    Li, Xinghua
    Jiang, Qi
    Zhang, Junwei
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (06) : 985 - 998
  • [28] An Attribute-based Access Control with Flexible Attribute Change in Open Systems
    Ye, Tao
    Cai, Yongquan
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON MECHATRONICS ENGINEERING AND INFORMATION TECHNOLOGY (ICMEIT 2017), 2017, 70 : 101 - 105
  • [29] Enforcing Scalable and Dynamic Hierarchical Access Control in Cloud Computing
    Yang, Ran
    Lin, Chuang
    Jiang, Yixin
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [30] Attribute-Based Data Sharing with Flexible and Direct Revocation in Cloud Computing
    Zhang, Yinghui
    Chen, Xiaofeng
    Li, Jin
    Li, Hui
    Li, Fenghua
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2014, 8 (11): : 4028 - 4049