首页> 外文会议>Asia Joint Conference on Information Security >An Identity Preserving Access Control Scheme with Flexible System Privilege Revocation in Cloud Computing
【24h】

An Identity Preserving Access Control Scheme with Flexible System Privilege Revocation in Cloud Computing

机译:云计算中具有灵活系统特权撤销功能的身份保存访问控制方案

获取原文

摘要

The advent of cloud computing motivates business organizations to migrate their complex data management systems from local servers to cloud servers for scalable and durable resources on pay per use basis. Considering enormous users and large amount of documents at cloud servers, there is a requirement of an access control scheme, which supports fine-grained cum flexible access control along with "Query-Response" mechanism to enable users to efficiently retrieve desired data from cloud servers. In addition, the scheme should support considerable flexibility to revoke system privileges from user, such as to restrict user from sharing or retrieving data or both, i.e., flexible system privilege revocation and most imperatively to preserve the identity of data owner and consumer, while sharing and retrieving data. Most of the access control schemes in cloud computing till date focus on restricting user from accessing data only. In this paper, we propose an identity preserving access control scheme to simultaneously realize the notion of scalability, fine-grained cum flexible access control, efficient data utilization, identity preserving and flexible system privilege revocation. We extend Ciphertext-Policy Attribute-Set-Based Encryption (CPASBE) in a hierarchical structure of users to achieve scalability. In addition, a hybridization of proxy re-encryption andand CP-ASBE is introduced to materialize the concept of CP-ASBE is introduced to materialize the concept of flexible system privilege revocation. Furthermore, we formally prove the security of our proposed scheme based on decisional bilinear Diffie-Hellman assumption. Efficacy of our scheme is depicted by performing comprehensive experiments.
机译:云计算的出现促使企业组织将其复杂的数据管理系统从本地服务器迁移到云服务器,以实现按使用付费的可扩展且持久的资源。考虑到云服务器上的大量用户和大量文档,需要一种访问控制方案,该方案支持细粒度且灵活的访问控制以及“查询-响应”机制,以使用户能够有效地从云服务器检索所需数据。另外,该方案应支持相当大的灵活性以撤消用户的系统特权,例如限制用户共享或检索数据或两者,即灵活的系统特权撤消,并且最重要的是在共享时保留数据所有者和消费者的身份和检索数据。迄今为止,云计算中的大多数访问控制方案都集中于限制用户仅访问数据。在本文中,我们提出了一种身份保存访问控制方案,以同时实现可伸缩性,细粒度和灵活的访问控制,高效的数据利用,身份保存和灵活的系统特权撤销的概念。我们在用户的层次结构中扩展了基于密文策略的基于属性集的加密(CPASBE),以实现可伸缩性。此外,还引入了代理重新加密和CP-ASBE的混合,以实现CP-ASBE的概念,以实现灵活的系统特权撤销的概念。此外,我们基于决策双线性Diffie-Hellman假设,正式证明了我们提出的方案的安全性。我们的方案的有效性通过进行全面的实验来描述。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号