Title
A Cryptographically Enforced Access Control with a Flexible User Revocation on Untrusted Cloud Storage.
Abstract
Cloud storage services have become ubiquitous. A large number of individuals and organizations are using them to store and share data, taking the benefits of mobility and affordability offered by these services. However, secure management of data in cloud storage services, more specifically supporting multi-party sharing in the context of a collaboration, is a challenging problem. The problem is further exacerbated if the data owner does not have any trust on the cloud storage providers and the data need regular updates from collaborating parties. A number of cryptographically enforced secure cloud storage solutions have been proposed to address this problem. One of the key issues with these solutions is the revocation of access to data for invalid users without moving the data (in the era of big data) and relying on the cloud service providers. In this paper, we introduce a cloud storage system that offers cryptographically enforced security. In contrast to other cryptographically protected cloud storage systems, our system supports a fine-grained access control mechanism and allows flexible revocations of invalid users without moving the data and relying on the cloud service providers. Our system employs an attribute-based encryption technique to support a complex access structure that allows a user to define human readable access policies to the data in the cloud storage. In addition, our system supports a flexible revocation scheme that can revoke invalid users directly by updating the revoked users’ list or indirectly by updating an epoch counter. The system administrator can choose one of these options flexibly depending on the needs. Our system also allows authorized users to update the encrypted data, and any users accessing such updated data in future can verify whether the data are modified by authorized users.
Year
DOI
Venue
2016
10.1007/s41019-016-0014-0
Data Science and Engineering
Keywords
Field
DocType
Cloud storage, Access control, Attribute-based encryption, Revocation
Data mining,Client-side encryption,Computer security,Computer science,Attribute-based encryption,Service provider,Access control,Data access,Big data,Cloud storage,Cloud computing
Journal
Volume
Issue
ISSN
1
3
2364-1541
Citations 
PageRank 
References 
2
0.36
27
Authors
2
Name
Order
Citations
PageRank
Jongkil Kim120.36
Surya Nepal21486186.76