• DocumentCode
    2445618
  • Title

    Fine-Grained Data Access Control Systems with User Accountability in Cloud Computing

  • Author

    Li, Jin ; Zhao, Gansen ; Chen, Xiaofeng ; Xie, Dongqing ; Rong, Chunming ; Li, Wenjun ; Tang, Lianzhang ; Tang, Yong

  • Author_Institution
    Sch. of Comput. Sci. & Educ. Softwar, Guangzhou Univ., Guangzhou, China
  • fYear
    2010
  • fDate
    Nov. 30 2010-Dec. 3 2010
  • Firstpage
    89
  • Lastpage
    96
  • Abstract
    Cloud computing is an emerging computing paradigm in which IT resources and capacities are provided as services over the Internet. Promising as it is, this paradigm also brings forth new challenges for data security and access control when users outsource sensitive data for sharing on cloud servers, which are likely outside of the same trust domain of data owners. To maintain the confidentiality of, sensitive user data against untrusted servers, existing work usually apply cryptographic methods by disclosing data decryption keys only to authorized users. However, in doing so, these solutions inevitably introduce heavy computation overhead on the data owner for key distribution and data management when fine-grained data access control is desired, and thus do not scale well. In this paper, we present a way to implement, scalable and fine-grained access control systems based on attribute-based encryption (ABE). For the purpose of secure access control in cloud computing, the prevention of illegal key sharing among colluding users is missing from the existing access control systems based on ABE. This paper addresses this challenging open issue by defining and enforcing access policies based on data attributes and implementing user accountability by using traitor tracing. Furthermore, both the user grant and revocation are efficiently supported by using the broadcast encryption technique. Extensive analysis shows that the proposed scheme is highly efficient and provably secure under existing security models.
  • Keywords
    Web services; access control; cloud computing; cryptography; information retrieval; attribute based encryption; cloud computing; data security; fine grained data access control system; secure access control; user accountability; Access control; Cloud computing; Encryption; Servers; Accountability; Attribute-based encryption; Fine-grained access control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2010 IEEE Second International Conference on
  • Conference_Location
    Indianapolis, IN
  • Print_ISBN
    978-1-4244-9405-7
  • Electronic_ISBN
    978-0-7695-4302-4
  • Type

    conf

  • DOI
    10.1109/CloudCom.2010.44
  • Filename
    5708438