Loading [MathJax]/extensions/MathMenu.js
Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud | IEEE Journals & Magazine | IEEE Xplore

Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud


Abstract:

Cloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also...Show More

Abstract:

Cloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient fine-grained access control and data sharing scheme for dynamic user groups by: 1) defining and enforcing access policies based on the attributes of the data; 2) permitting the key generation center to efficiently update user credentials for dynamic user groups; and 3) allowing some expensive computation tasks to be performed by untrusted CSPs without requiring any delegation key. Specifically, we first design an efficient revocable attribute-based encryption (ABE) scheme with the property of ciphertext delegation by exploiting and uniquely combining techniques of identity-based encryption, ABE, subset-cover framework, and ciphertext encoding mechanism. We then present a fine-grained access control and data sharing system for on-demand services with dynamic user groups in the cloud. The experimental data show that our proposed scheme is more efficient and scalable than the state-of-the-art solution.
Published in: IEEE Transactions on Information Forensics and Security ( Volume: 13, Issue: 8, August 2018)
Page(s): 2101 - 2113
Date of Publication: 27 February 2018

ISSN Information:


I. Introduction

Cloud computing is widely accepted as a new computing paradigm due to its intrinsic resource-sharing and low maintenance characteristics. In cloud computing, the CSPs, such as Amazons EC2 and S3, Google App Engine, and Microsoft Azure, are able to deliver various services, including software as a service (SaaS), platform as a service (PaaS) and infrastructure as a service (IaaS), to cloud users. By migrating the local data management system into cloud storage, users can enjoy cost savings and productivity enhancements by using cloud-based services to manage projects and establish collaborations. With the increasing development of cloud computing technologies, it is not hard to imagine that in the near future more and more businesses will be moved into the cloud.

Contact IEEE to Subscribe

References

References is not available for this document.