PriGuarder: A Privacy-Aware Access Control Approach Based on Attribute Fuzzy Grouping in Cloud Environments

被引:6
|
作者
Lin, Li [1 ,2 ,3 ]
Liu, Ting-Ting [1 ,2 ]
Li, Shuang [1 ,2 ]
Magurawalage, Chathura M. Sarathchandra [4 ]
Tu, Shan-Shan [1 ,2 ]
机构
[1] Beijing Univ Technol, Fac Informat Technol, Coll Comp Sci, Beijing 100124, Peoples R China
[2] Beijing Key Lab Trusted Comp, Beijing 100124, Peoples R China
[3] Natl Engn Lab Classified Informat Secur Protect, Beijing 100124, Peoples R China
[4] Univ Essex, Dept Comp Sci & Elect Engn, Colchester CO4 3SQ, Essex, England
来源
IEEE ACCESS | 2018年 / 6卷
基金
美国国家科学基金会;
关键词
Data privacy protection; access control; attribute fuzzy grouping; MULTI-AUTHORITY; ENCRYPTION; SYSTEMS; STORAGE;
D O I
10.1109/ACCESS.2017.2780763
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data privacy protection is crucial to cloud computing since privacy leakage may prevent users from using cloud services. To ensure data privacy, we propose PriGuarder, a novel privacy-aware access control method. This method spans the three stages of a cloud service, i.e., user registration, data creation, and data access. At each stage, users can choose two modes to interact with the cloud service provider, i.e., direct or indirect. With the indirect mode, an attribute fuzzy grouping scheme is introduced to ensure user identity privacy and attribute privacy in all the three stages. Furthermore, exploiting data encryption and timestamp techniques, new access control protocols are proposed to regulate interactions between users and the cloud service provider. We illustrate the use of our method in the context of Amazon S3. Theoretical analysis and comprehensive simulation experiments have been conducted, which demonstrate the efficacy of PriGuarder.
引用
收藏
页码:1882 / 1893
页数:12
相关论文
共 50 条
  • [31] Privacy-aware collaborative access control in Web-based Social Networks
    Carminati, Barbara
    Ferrari, Elena
    DATA AND APPLICATIONS SECURITY XXII, 2008, 5094 : 81 - 96
  • [32] A privacy-aware continuous authentication scheme for proximity-based access control
    Agudo, Isaac
    Rios, Ruben
    Lopez, Javier
    COMPUTERS & SECURITY, 2013, 39 : 117 - 126
  • [33] A Privacy-aware Graph-based Access Control System for the Healthcare Domain
    Tian, Yuan
    Song, Biao
    Hassan, M. Mehedi
    Huh, Eui-Nam
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2012, 6 (10): : 2708 - 2730
  • [34] Risk-Based Privacy-Aware Access Control for Threat Detection Systems
    Metoui, Nadia
    Bezzi, Michele
    Armando, Alessandro
    TRANSACTIONS ON LARGE-SCALE DATA- AND KNOWLEDGECENTERED SYSTEMS XXXVI: SPECIAL ISSUE ON DATA AND SECURITY ENGINEERING, 2018, 10720 : 1 - 30
  • [35] Privacy-aware access control with trust management in web service
    Li, Min
    Sun, Xiaoxun
    Wang, Hua
    Zhang, Yanchun
    Zhang, Ji
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2011, 14 (04): : 407 - 430
  • [36] A privacy-aware access control model for distributed network monitoring
    Papagiannakopoulou, Eugenia I.
    Koukovini, Maria N.
    Lioudakis, Georgios V.
    Garcia-Alfaro, Joaquin
    Kaklamani, Dimitra I.
    Venieris, Iakovos S.
    Cuppens, Frederic
    Cuppens-Boulahia, Nora
    COMPUTERS & ELECTRICAL ENGINEERING, 2013, 39 (07) : 2263 - 2281
  • [37] Privacy query rewriting algorithm instrumented by a privacy-aware access control model
    Oulmakhzoune, Said
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    Morucci, Stephane
    Barhamgi, Mahmoud
    Benslimane, Djamal
    ANNALS OF TELECOMMUNICATIONS, 2014, 69 (1-2) : 3 - 19
  • [38] Privacy query rewriting algorithm instrumented by a privacy-aware access control model
    Said Oulmakhzoune
    Nora Cuppens-Boulahia
    Frédéric Cuppens
    Stéphane Morucci
    Mahmoud Barhamgi
    Djamal Benslimane
    annals of telecommunications - annales des télécommunications, 2014, 69 : 3 - 19
  • [39] Assurance, Consent and Access Control for Privacy-Aware OIDC Deployments
    Sassetti, Gianluca
    Sharif, Amir
    Sciarretta, Giada
    Carbone, Roberto
    Ranise, Silvio
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVII, DBSEC 2023, 2023, 13942 : 203 - 222
  • [40] Privacy-aware access control with trust management in web service
    Min Li
    Xiaoxun Sun
    Hua Wang
    Yanchun Zhang
    Ji Zhang
    World Wide Web, 2011, 14 : 407 - 430