DocumentCode :
2427669
Title :
Hierarchical Attribute-Based Access Control with Authentication for Outsourced Data in Cloud Computing
Author :
Xuejiao Liu ; Yingjie Xia ; Shasha Jiang ; Fubiao Xia ; Yanbo Wang
Author_Institution :
Inst. of Service Eng., Hangzhou Normal Univ., Hangzhou, China
fYear :
2013
fDate :
16-18 July 2013
Firstpage :
477
Lastpage :
484
Abstract :
Access control is one of the most important security mechanisms in cloud computing. Attributed based encryption provides an approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore flexible authorization in specifying the data user´s privileges and enforcing the data owner´s policy in cloud based environments. In this paper, we propose a hierarchical attribute based access control scheme by extending ciphertext-policy attribute-based encryption (CP-ABE) with a hierarchical structure of multiauthorities and exploiting attribute-based signature (ABS). The proposed scheme not only achieves scalability due to its hierarchical structure, but also inherits fine-grained access control with authentication in supporting write privilege on outsourced data in cloud computing. In addition, we decouple the task of policy management from security enforcement by using the extensible access control markup language (XACML) framework. Extensive analysis shows that our scheme is both efficient and scalable in dealing with access control for outsourced data in cloud computing.
Keywords :
XML; authorisation; cloud computing; cryptography; digital signatures; ABS; CP-ABE; XACML framework; attribute-based signature; authentication; ciphertext-policy attribute-based encryption; cloud computing; data access policies; data owner policy; data user privileges; extensible access control markup language; fine-grained access control; hierarchical attribute-based access control; multiauthorities hierarchical structure; security enforcement; security mechanisms; Access control; Authentication; Cloud computing; Encryption; Servers; ABS; Access Control; CP-ABE; XACML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference on
Conference_Location :
Melbourne, VIC
Type :
conf
DOI :
10.1109/TrustCom.2013.60
Filename :
6680877
Link To Document :
بازگشت