CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage

被引:55
|
作者
Ning, Jianting [1 ]
Cao, Zhenfu [2 ]
Dong, Xiaolei [2 ]
Liang, Kaitai [3 ]
Wei, Lifei [4 ]
Choo, Kim-Kwang Raymond [5 ]
机构
[1] Natl Univ Singapore, Dept Comp Sci, Singapore 119077, Singapore
[2] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
[3] Univ Surrey, Dept Comp Sci, Guildford GU2 7XH, Surrey, England
[4] Shanghai Ocean Univ, Sch Informat Technol, Shanghai 201306, Peoples R China
[5] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
基金
英国工程与自然科学研究理事会; 新加坡国家研究基金会; 中国国家自然科学基金;
关键词
Secure cloud storage; ciphertext-policy attribute-based encryption; access credentials misuse; traceability and revocation; auditing; ATTRIBUTE-BASED ENCRYPTION; EFFICIENT; PRIVACY;
D O I
10.1109/TSC.2018.2791538
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Secure cloud storage, which is an emerging cloud service, is designed to protect the confidentiality of outsourced data but also to provide flexible data access for cloud users whose data is out of physical control. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is regarded as one of the most promising techniques that may be leveraged to secure the guarantee of the service. However, the use of CP-ABE may yield an inevitable security breach which is known as the misuse of access credential (i.e., decryption rights), due to the intrinsic "all-or-nothing" decryption feature of CP-ABE. In this paper, we investigate the two main cases of access credential misuse: one is on the semi-trusted authority side, and the other is on the side of cloud user. To mitigate the misuse, we propose the first accountable authority and revocable CP-ABE based cloud storage system with white-box traceability and auditing, referred to as CryptCloud(+). We also present the security analysis and further demonstrate the utility of our system via experiments.
引用
收藏
页码:111 / 124
页数:14
相关论文
共 50 条
  • [21] A Secure Cloud Storage Framework With Access Control Based on Blockchain
    Wang, Shangping
    Wang, Xu
    Zhang, Yaling
    IEEE ACCESS, 2019, 7 : 112713 - 112725
  • [22] Secure Updatable Storage Access Control System for EHRs in the Cloud
    Wang, Jingwei
    Yin, Xinchun
    Ning, Jianting
    Xu, Shengmin
    Xu, Guowen
    Huang, Xinyi
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (04) : 2939 - 2953
  • [23] Domain Based Storage Protection with Secure Access Control for the Cloud
    Paladi, Nicolae
    Michalas, Antonis
    Gehrmann, Christian
    SCC'14: PROCEEDINGS OF THE 2ND INTERNATIONAL WORKSHOP ON SECURITY IN CLOUD COMPUTING, 2014, : 35 - 42
  • [24] Secure Overlay Cloud Storage with Access Control and Assured Deletion
    Tang, Yang
    Lee, Patrick P. C.
    Lui, John C. S.
    Perlman, Radia
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2012, 9 (06) : 903 - 916
  • [25] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou Yousheng
    Chen Lujun
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (07) : 1856 - 1863
  • [26] Trust aware cryptographic role based access control scheme for secure cloud data storage
    Dayana, K. Roslin
    Rani, P. Shobha
    AUTOMATIKA, 2023, 64 (04) : 1072 - 1079
  • [27] Integrating Trust with Cryptographic Role-based Access Control for Secure Cloud Data Storage
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 560 - 569
  • [28] Secure Storage and Deletion Based on Blockchain for Cloud Data with Fine-grained Access Control
    Zhou, Yousheng
    Chen, Lüjun
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2021, 43 (07): : 1856 - 1863
  • [29] Trust Enhanced Cryptographic Role-Based Access Control for Secure Cloud Data Storage
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (11) : 2381 - 2395
  • [30] SECURE ACCESS MECHANISM FOR CLOUD STORAGE
    Harnik, Danny
    Kolodner, Elliot K.
    Ronen, Shahar
    Satran, Julian
    Shulman-Peleg, Alexandra
    Tal, Sivan
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2011, 12 (03): : 317 - 336