Title :
Hierarchical Attribute-Based Access Control with Authentication for Outsourced Data in Cloud Computing
Author :
Xuejiao Liu ; Yingjie Xia ; Shasha Jiang ; Fubiao Xia ; Yanbo Wang
Author_Institution :
Inst. of Service Eng., Hangzhou Normal Univ., Hangzhou, China
Abstract :
Access control is one of the most important security mechanisms in cloud computing. Attributed based encryption provides an approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore flexible authorization in specifying the data user´s privileges and enforcing the data owner´s policy in cloud based environments. In this paper, we propose a hierarchical attribute based access control scheme by extending ciphertext-policy attribute-based encryption (CP-ABE) with a hierarchical structure of multiauthorities and exploiting attribute-based signature (ABS). The proposed scheme not only achieves scalability due to its hierarchical structure, but also inherits fine-grained access control with authentication in supporting write privilege on outsourced data in cloud computing. In addition, we decouple the task of policy management from security enforcement by using the extensible access control markup language (XACML) framework. Extensive analysis shows that our scheme is both efficient and scalable in dealing with access control for outsourced data in cloud computing.
Keywords :
XML; authorisation; cloud computing; cryptography; digital signatures; ABS; CP-ABE; XACML framework; attribute-based signature; authentication; ciphertext-policy attribute-based encryption; cloud computing; data access policies; data owner policy; data user privileges; extensible access control markup language; fine-grained access control; hierarchical attribute-based access control; multiauthorities hierarchical structure; security enforcement; security mechanisms; Access control; Authentication; Cloud computing; Encryption; Servers; ABS; Access Control; CP-ABE; XACML;
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference on
Conference_Location :
Melbourne, VIC
DOI :
10.1109/TrustCom.2013.60