Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing

Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
复制标题

DOI:
10.1109/infcom.2010.5462174
复制
发表时间:
2010-03
期刊:
2010 Proceedings IEEE INFOCOM
影响因子:
--
通讯作者:
Shucheng Yu;Cong Wang-;K. Ren;Wenjing Lou
Shucheng Yu;Cong Wang-;K. Ren;Wenjing Lou
中科院分区:
其他
文献类型:
--
作者:
Shucheng Yu;Cong Wang-;K. Ren;Wenjing Lou

文献摘要

被引文献

相似文献

云计算是一种新兴的计算范式,其中为Internet提供了计算基础架构的资源。尽管如此,此范式也很有希望,在用户外包敏感数据以在云服务器上共享的敏感数据时,这一范式也带来了许多新的挑战,这些挑战与云服务器共享,而云服务器与数据所有者不在同一受信任的域内。为了将敏感的用户数据保密于不受信任的服务器,现有解决方案通常通过仅向授权用户披露数据解密键来应用加密方法。但是,在这样做的过程中,当需要细粒度的数据访问控制时,这些解决方案不可避免地会在数据所有者上引入大量计算开销,以进行密钥分布和数据管理,因此扩展不佳。实际上,同时达到访问控制的细粒度,可扩展性和数据机密性的问题实际上仍未解决。本文通过一方面根据数据属性来定义和执行访问策略,解决了这个具有挑战性的开放问题,另一方面,允许数据所有者委托涉及细粒度数据访问控制的大多数计算任务不受信任的云服务器而没有披露基本数据内容。我们通过利用和唯一结合基于属性的加密技术(ABE),代理重新加热和懒惰的重新加热来实现这一目标。我们提出的计划还具有用户访问特权机密性和用户秘密密钥问责制的显着属性。广泛的分析表明,在现有的安全模型下,我们提出的计划非常有效,并且可以证明是安全的。
Cloud computing is an emerging computing paradigm in which resources of the computing infrastructure are provided as services over the Internet. As promising as it is, this paradigm also brings forth many new challenges for data security and access control when users outsource sensitive data for sharing on cloud servers, which are not within the same trusted domain as data owners. To keep sensitive user data confidential against untrusted servers, existing solutions usually apply cryptographic methods by disclosing data decryption keys only to authorized users. However, in doing so, these solutions inevitably introduce a heavy computation overhead on the data owner for key distribution and data management when fine-grained data access control is desired, and thus do not scale well. The problem of simultaneously achieving fine-grainedness, scalability, and data confidentiality of access control actually still remains unresolved. This paper addresses this challenging open issue by, on one hand, defining and enforcing access policies based on data attributes, and, on the other hand, allowing the data owner to delegate most of the computation tasks involved in fine-grained data access control to untrusted cloud servers without disclosing the underlying data contents. We achieve this goal by exploiting and uniquely combining techniques of attribute-based encryption (ABE), proxy re-encryption, and lazy re-encryption. Our proposed scheme also has salient properties of user access privilege confidentiality and user secret key accountability. Extensive analysis shows that our proposed scheme is highly efficient and provably secure under existing security models.