K2C: Cryptographic Cloud Storage with Lazy Revocation and Anonymous Access
K2C: Cryptographic Cloud Storage with Lazy Revocation and Anonymous Access
复制标题
DOI:
10.1007/978-3-642-31909-9_4
复制
发表时间:
2011-09
期刊:
影响因子:
--
通讯作者:
Saman Zarandioon;D. Yao;V. Ganapathy
中科院分区:
文献类型:
--
作者:
Saman Zarandioon;D. Yao;V. Ganapathy
Security and privacy concerns hinder the adoption of cloud storage and computing in sensitive environments. We present a user-centric privacy-preserving cryptographic access control protocol calledK2C(Key To Cloud) that enables end-users to securely store, share, and manage their sensitive data in an untrusted cloud storage anonymously.K2Cis scalable and supports the lazy revocation. It can be easily implemented on top of existing cloud services and APIs – we demonstrate its prototype based on Amazon S3 API.K2Cis realized through our new cryptographic key-updating scheme, referred to asAB−HKU. The main advantage of theAB−HKUscheme is that it supports efficient delegation and revocation of privileges for hierarchies without requiring complex cryptographic data structures. We analyze the security and performance of our access control protocol, and provide an open source implementation. Two cryptographic libraries, Hierarchical Identity-Based Encryption and Key-Policy Attribute-Based Encryption, developed in this project are useful beyond the specific cloud security problem studied.