Privacy Preserving Delegated Access Control in Public Clouds

被引:46
|
作者
Nabeel, Mohamed [1 ]
Bertino, Elisa [1 ]
机构
[1] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
关键词
Privacy; identity; cloud computing; policy decomposition; encryption; access control;
D O I
10.1109/TKDE.2013.68
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Current approaches to enforce fine-grained access control on confidential data hosted in the cloud are based on fine-grained encryption of the data. Under such approaches, data owners are in charge of encrypting the data before uploading them on the cloud and re-encrypting the data whenever user credentials change. Data owners thus incur high communication and computation costs. A better approach should delegate the enforcement of fine-grained access control to the cloud, so to minimize the overhead at the data owners, while assuring data confidentiality from the cloud. We propose an approach, based on two layers of encryption, that addresses such requirement. Under our approach, the data owner performs a coarse-grained encryption, whereas the cloud performs a fine-grained encryption on top of the owner encrypted data. A challenging issue is how to decompose access control policies (ACPs) such that the two layer encryption can be performed. We show that this problem is NP-complete and propose novel optimization algorithms. We utilize an efficient group key management scheme that supports expressive ACPs. Our system assures the confidentiality of the data and preserves the privacy of users from the cloud while delegating most of the access control enforcement to the cloud.
引用
收藏
页码:2268 / 2280
页数:13
相关论文
共 50 条
  • [3] Privacy Preserving Delegated Access Control in the Storage as a Service Model
    Nabeel, Mohamed
    Bertino, Elisa
    [J]. 2012 IEEE 13TH INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI), 2012, : 645 - 652
  • [4] Auditing Revocable Privacy-Preserving Access Control for EHRs in Clouds
    Liu, Weiran
    Liu, Xiao
    Liu, Jianwei
    Wu, Qianhong
    [J]. COMPUTER JOURNAL, 2017, 60 (12): : 1871 - 1888
  • [5] PAbAC: A Privacy Preserving Attribute based Framework for Fine Grained Access Control in Clouds
    Belguith, Sana
    Kaaniche, Nesrine
    Jemai, Abderrazak
    Laurent, Maryline
    Attia, Rabah
    [J]. SECRYPT: PROCEEDINGS OF THE 13TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS - VOL. 4, 2016, : 133 - 146
  • [6] Privacy Preserving Delegated Word Search in the Cloud
    Elkhiyaoui, Kaoutar
    Onen, Melek
    Molva, Refik
    [J]. 2014 11TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY (SECRYPT), 2014, : 137 - 150
  • [7] Merx: Secure and Privacy Preserving Delegated Payments
    Soghoian, Christopher
    Aad, Imad
    [J]. TRUSTED COMPUTING, PROCEEDINGS, 2009, 5471 : 217 - +
  • [8] PAC: Privacy preserving proxy re-encryption for access control in public cloud
    Chaudhari, Payal
    Das, Manik Lal
    [J]. INFORMATION SECURITY JOURNAL, 2022, 31 (05): : 612 - 627
  • [9] Delegation of access rights in a privacy preserving access control model
    Moniruzzaman, Md
    Barker, Ken
    [J]. 2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2011, : 124 - 133
  • [10] Privacy-preserving auditing scheme for shared data in public clouds
    Libing Wu
    Jing Wang
    Sherali Zeadally
    Debiao He
    [J]. The Journal of Supercomputing, 2018, 74 : 6156 - 6183