CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage

被引:55
|
作者
Ning, Jianting [1 ]
Cao, Zhenfu [2 ]
Dong, Xiaolei [2 ]
Liang, Kaitai [3 ]
Wei, Lifei [4 ]
Choo, Kim-Kwang Raymond [5 ]
机构
[1] Natl Univ Singapore, Dept Comp Sci, Singapore 119077, Singapore
[2] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
[3] Univ Surrey, Dept Comp Sci, Guildford GU2 7XH, Surrey, England
[4] Shanghai Ocean Univ, Sch Informat Technol, Shanghai 201306, Peoples R China
[5] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
基金
英国工程与自然科学研究理事会; 新加坡国家研究基金会; 中国国家自然科学基金;
关键词
Secure cloud storage; ciphertext-policy attribute-based encryption; access credentials misuse; traceability and revocation; auditing; ATTRIBUTE-BASED ENCRYPTION; EFFICIENT; PRIVACY;
D O I
10.1109/TSC.2018.2791538
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Secure cloud storage, which is an emerging cloud service, is designed to protect the confidentiality of outsourced data but also to provide flexible data access for cloud users whose data is out of physical control. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is regarded as one of the most promising techniques that may be leveraged to secure the guarantee of the service. However, the use of CP-ABE may yield an inevitable security breach which is known as the misuse of access credential (i.e., decryption rights), due to the intrinsic "all-or-nothing" decryption feature of CP-ABE. In this paper, we investigate the two main cases of access credential misuse: one is on the semi-trusted authority side, and the other is on the side of cloud user. To mitigate the misuse, we propose the first accountable authority and revocable CP-ABE based cloud storage system with white-box traceability and auditing, referred to as CryptCloud(+). We also present the security analysis and further demonstrate the utility of our system via experiments.
引用
收藏
页码:111 / 124
页数:14
相关论文
共 50 条
  • [31] Secure Data Collection, Storage, and Access in Cloud-Assisted IoT
    Wang, Wei
    Xu, Peng
    Yang, Laurence Tianruo
    IEEE CLOUD COMPUTING, 2018, 5 (04): : 77 - 88
  • [32] Secure Cloud Storage of Data
    Dongre, Kirti A.
    Thakur, Roshan Singh
    Abraham, Allan
    2014 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2014,
  • [33] Developing Secure Cloud Storage System Using Access Control Models
    Ubale, S. A.
    Apte, S. S.
    Bokefode, J. D.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON DATA ENGINEERING AND COMMUNICATION TECHNOLOGY, ICDECT 2016, VOL 2, 2017, 469 : 141 - 147
  • [34] ESSAC: Enhanced Scalable Secure Access Control Framework for Cloud Storage
    Hassan, Hatem
    Mostafa, Ahmad
    Shawish, Ahmed
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS (ICFNDS '17), 2017,
  • [35] Provably Secure Data Access Control Protocol for Cloud Computing
    Zhang, Ji
    Chen, Anmin
    Zhang, Ping
    SYMMETRY-BASEL, 2023, 15 (12):
  • [36] Statistical privacy protection for secure data access control in cloud ☆
    Baseri, Yaser
    Hafid, Abdelhakim
    Firoozjaei, Mahdi Daghmehchi
    Cherkaoui, Soumaya
    Ray, Indrakshi
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 84
  • [37] Data access control method of cloud network secure storage under Social Internet of Things environment
    Wu, Huifen
    Ye, Wei
    Guo, Yaqiong
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2023, 14 (04) : 1379 - 1386
  • [38] Secure Outsourced Medical Data against Unexpected Leakage with Flexible Access Control in a Cloud Storage System
    Zhou, Xingguang
    Liu, Jianwei
    Zhang, Zongyang
    Wu, Qianhong
    SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [39] Trust-based Secure Cloud Data Storage with Cryptographic Role-based Access Control
    Zhou, Lan
    Varadharajan, Vijay
    Hitchens, Michael
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY (SECRYPT 2013), 2013, : 62 - 73
  • [40] Data access control method of cloud network secure storage under Social Internet of Things environment
    Huifen Wu
    Wei Ye
    Yaqiong Guo
    International Journal of System Assurance Engineering and Management, 2023, 14 : 1379 - 1386