CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage

被引:50
|
作者
Ning, Jianting [1 ]
Cao, Zhenfu [2 ]
Dong, Xiaolei [2 ]
Liang, Kaitai [3 ]
Wei, Lifei [4 ]
Choo, Kim-Kwang Raymond [5 ]
机构
[1] Natl Univ Singapore, Dept Comp Sci, Singapore 119077, Singapore
[2] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
[3] Univ Surrey, Dept Comp Sci, Guildford GU2 7XH, Surrey, England
[4] Shanghai Ocean Univ, Sch Informat Technol, Shanghai 201306, Peoples R China
[5] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
基金
中国国家自然科学基金; 英国工程与自然科学研究理事会; 新加坡国家研究基金会;
关键词
Secure cloud storage; ciphertext-policy attribute-based encryption; access credentials misuse; traceability and revocation; auditing; ATTRIBUTE-BASED ENCRYPTION; EFFICIENT; PRIVACY;
D O I
10.1109/TSC.2018.2791538
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Secure cloud storage, which is an emerging cloud service, is designed to protect the confidentiality of outsourced data but also to provide flexible data access for cloud users whose data is out of physical control. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is regarded as one of the most promising techniques that may be leveraged to secure the guarantee of the service. However, the use of CP-ABE may yield an inevitable security breach which is known as the misuse of access credential (i.e., decryption rights), due to the intrinsic "all-or-nothing" decryption feature of CP-ABE. In this paper, we investigate the two main cases of access credential misuse: one is on the semi-trusted authority side, and the other is on the side of cloud user. To mitigate the misuse, we propose the first accountable authority and revocable CP-ABE based cloud storage system with white-box traceability and auditing, referred to as CryptCloud(+). We also present the security analysis and further demonstrate the utility of our system via experiments.
引用
下载
收藏
页码:111 / 124
页数:14
相关论文
共 50 条
  • [41] DFCloud : A TPM-based Secure Data Access Control Method of Cloud Storage in Mobile Devices
    Shin, Jaebok
    Kim, Yungu
    Park, Wooram
    Park, Chanik
    2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [42] Achieving Lightweight, Time-Specific and Secure Access Control in Cloud Storage
    Wang, Yanchao
    Li, Fenghua
    Niu, Ben
    Xie, Rongna
    2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [43] Secure and Efficient Attribute-Based Access Control for Multiauthority Cloud Storage
    Wei, Jianghong
    Liu, Wenfen
    Hu, Xuexian
    IEEE SYSTEMS JOURNAL, 2018, 12 (02): : 1731 - 1742
  • [44] Effective and Secure Access Control for Multi-Authority Cloud Storage Systems
    Xin, Lin
    Sun, Xingming
    Fu, Zhangjie
    Zhang, Liang-Ao
    Xi, Jie
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (02): : 217 - 236
  • [45] A robust and secure multi-authority access control system for cloud storage
    Jin Gu
    Jianqiang Shen
    Baoyun Wang
    Peer-to-Peer Networking and Applications, 2021, 14 : 1488 - 1499
  • [46] Semantically Rich, Oblivious Access Control Using ABAC for Secure Cloud Storage
    Joshi, Maithilee
    Mittal, Sudip
    Joshi, Karuna P.
    Finin, Tim
    2017 IEEE 1ST INTERNATIONAL CONFERENCE ON EDGE COMPUTING (IEEE EDGE), 2017, : 142 - 149
  • [47] A robust and secure multi-authority access control system for cloud storage
    Gu, Jin
    Shen, Jianqiang
    Wang, Baoyun
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (03) : 1488 - 1499
  • [48] Secure Cloud Storage Model with Hidden Policy Attribute based Access Control
    Sowmiya, M.
    Adimoolam, M.
    2014 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN INFORMATION TECHNOLOGY (ICRTIT), 2014,
  • [49] Secure storage of data in cloud computing
    20150500466883
    (1) School of Computer and Software and Jiangsu Engineering Center of Network Monitoring, Nanjing University of Information Science and Technology, Nanjing; 210044, China, 1600, IEEE Tainan Section; International Society of Management Engineers; JSPS/NSFC/NRF A3 Foresight Program Ultra-Realistic Acoustic Interactive Communication on Next-Generation Internet; Tainan Chapter of IEEE Signal Processing Society; Waseda University (Institute of Electrical and Electronics Engineers Inc.):
  • [50] Anonymous Authentication for Secure Data Stored on Cloud with Decentralized Access Control
    Mokle, Shraddha
    Shaikh, Nuzhat F.
    PROCEEDINGS OF THE 2016 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2016, : 216 - 220