首页> 外文期刊>International Journal of Computer Trends and Technology >Secure Role based Data Access Control in Cloud Computing
【24h】

Secure Role based Data Access Control in Cloud Computing

机译:云计算中基于角色的安全数据访问控制

获取原文
           

摘要

Cloud computing is an emerging computing paradigm in which resources of the computing infrastructure are provided as services over the Internet. As promising as it is, this paradigm also brings forth many new challenges for data security and access control when users outsource sensitive data for sharing on cloud servers, which are not within the same trusted domain as data owners. To keep sensitive user data confidential against untrusted servers, existing solutions usually apply cryptographic methods by disclosing data decryption keys only to authorized users. However, in doing so, these solutions inevitably introduce a heavy computation overhead on the data owner for key distribution and data management when fine grained data access control is desired, and thus do not scale well. The problem of simultaneously achieving finegrainedness, scalability, and data confidentiality of access control actually still remains unresolved. This paper addresses this challenging open issue by, on one hand, defining and enforcing access policies based on data attributes, and, on the other hand, allowing the data owner to delegate most of the computation tasks involved in fine grained data access control to untrusted cloud servers without disclosing the underlying data contents. We achieve this goal by exploiting and uniquely combining techniques of attributebased encryption (ABE), proxy reencryption, and lazy reencryption. Our proposed scheme also has salient properties of user access privilege confidentiality and user secret key accountability. Exten sive analysis shows that our proposed scheme is highly efficient and provably secure under existing security models.
机译:云计算是一种新兴的计算范例,其中计算基础结构的资源作为服务通过Internet提供。当用户将敏感数据外包给云服务器上的共享资源时(与数据所有者不在同一个受信任域中),这种范例虽然很有希望,但它也给数据安全和访问控制带来了许多新挑战。为了使敏感用户数据对不受信任的服务器保密,现有的解决方案通常通过仅向授权用户公开数据解密密钥来应用加密方法。但是,这样做时,当需要细粒度的数据访问控制时,这些解决方案不可避免地会给数据所有者带来繁重的计算开销,以进行密钥分发和数据管理,因此无法很好地扩展。同时实现访问控制的细粒度,可伸缩性和数据机密性的问题实际上仍然没有解决。本文一方面通过基于数据属性定义和实施访问策略来解决这一具有挑战性的开放性问题,另一方面,允许数据所有者将细粒度数据访问控制中涉及的大多数计算任务委托给不受信任的对象。云服务器,而不会公开基础数据内容。我们通过利用和独特地组合基于属性的加密(ABE),代理重新加密和惰性重新加密的技术来实现此目标。我们提出的方案还具有用户访问特权保密性和用户秘密密钥责任制的显着特性。广泛的分析表明,我们提出的方案在现有安全模型下是高效且可证明的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号