CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage

被引:50
|
作者
Ning, Jianting [1 ]
Cao, Zhenfu [2 ]
Dong, Xiaolei [2 ]
Liang, Kaitai [3 ]
Wei, Lifei [4 ]
Choo, Kim-Kwang Raymond [5 ]
机构
[1] Natl Univ Singapore, Dept Comp Sci, Singapore 119077, Singapore
[2] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
[3] Univ Surrey, Dept Comp Sci, Guildford GU2 7XH, Surrey, England
[4] Shanghai Ocean Univ, Sch Informat Technol, Shanghai 201306, Peoples R China
[5] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
基金
中国国家自然科学基金; 英国工程与自然科学研究理事会; 新加坡国家研究基金会;
关键词
Secure cloud storage; ciphertext-policy attribute-based encryption; access credentials misuse; traceability and revocation; auditing; ATTRIBUTE-BASED ENCRYPTION; EFFICIENT; PRIVACY;
D O I
10.1109/TSC.2018.2791538
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Secure cloud storage, which is an emerging cloud service, is designed to protect the confidentiality of outsourced data but also to provide flexible data access for cloud users whose data is out of physical control. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is regarded as one of the most promising techniques that may be leveraged to secure the guarantee of the service. However, the use of CP-ABE may yield an inevitable security breach which is known as the misuse of access credential (i.e., decryption rights), due to the intrinsic "all-or-nothing" decryption feature of CP-ABE. In this paper, we investigate the two main cases of access credential misuse: one is on the semi-trusted authority side, and the other is on the side of cloud user. To mitigate the misuse, we propose the first accountable authority and revocable CP-ABE based cloud storage system with white-box traceability and auditing, referred to as CryptCloud(+). We also present the security analysis and further demonstrate the utility of our system via experiments.
引用
下载
收藏
页码:111 / 124
页数:14
相关论文
共 50 条
  • [1] An Improvement on "CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage"
    Cheng, Leixiao
    Meng, Fei
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (03) : 1662 - 1663
  • [2] Secure Data Deduplication With Dynamic Access Control for Mobile Cloud Storage
    Qi, Saiyu
    Wei, Wei
    Wang, Jianfeng
    Sun, Shifeng
    Rutkowski, Leszek
    Huang, Tingwen
    Kacprzyk, Janusz
    Qi, Yong
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (04) : 2566 - 2582
  • [3] The research and prospect of secure data access control in cloud storage environment
    Li, Tengfei
    Hu, Liang
    Li, Yan
    Chu, Jianfeng
    Li, Hongtu
    Han, Hongying
    Journal of Communications, 2015, 10 (10): : 753 - 759
  • [4] Expressive, Efficient, and Revocable Data Access Control for Multi-Authority Cloud Storage
    Yang, Kan
    Jia, Xiaohua
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (07) : 1735 - 1744
  • [5] Blockchain based Secure Data Storage and Access Control System using Cloud
    Desai, Shubham
    Deshmukh, Onkar
    Shelke, Rahul
    Choudhary, Harish
    Sambhare, S. S.
    Yadav, Arjunsingh
    2019 5TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, CONTROL AND AUTOMATION (ICCUBEA), 2019,
  • [6] Enforcing Role-Based Access Control for Secure Data Storage in the Cloud
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    COMPUTER JOURNAL, 2011, 54 (10): : 1675 - 1687
  • [7] A Survey: Secure Cloud Data Storage and Access Control System Using Blockchain
    Patel, Kashyap
    Modi, Ritiksha
    Sharma, Shital
    Patel, Minal
    SOFT COMPUTING FOR SECURITY APPLICATIONS, ICSCS 2022, 2023, 1428 : 195 - 207
  • [8] Secure cloud storage using anonymous and blackbox traceable data access control
    Wu, Songyang
    Zhang, Yong
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (18) : 4308 - 4318
  • [9] Secure Data Access and Sharing Scheme for Cloud Storage
    Xiong Li
    Saru Kumari
    Jian Shen
    Fan Wu
    Caisen Chen
    SK Hafizul Islam
    Wireless Personal Communications, 2017, 96 : 5295 - 5314
  • [10] Secure Data Access and Sharing Scheme for Cloud Storage
    Li, Xiong
    Kumari, Saru
    Shen, Jian
    Wu, Fan
    Chen, Caisen
    Islam, S. K. Hafizul
    WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (04) : 5295 - 5314