• DocumentCode
    2843503
  • Title

    Access Control as a Service for Public Cloud Storage

  • Author

    Zhang, Yang ; Chen, Jun-liang

  • Author_Institution
    State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2012
  • fDate
    18-21 June 2012
  • Firstpage
    526
  • Lastpage
    536
  • Abstract
    With the rapid application of service-oriented technologies, service and data outsourcing has become a practical and useful computing paradigm. Combined use of access control and cryptography was proposed by many researchers to protect sensitive information in this outsourcing scenario. However, the rigid combination in existing approaches has difficulty in satisfying the flexibility requirement of access control for diverse applications. In this paper, we propose an access control service for public cloud storage, where authorization is controlled by the data owner, and the PDP (Policy Decision Point) and PEP (Policy Enforcement Point) can be securely delegated. In order to implement the service, an attribute-full proxy re-encryption scheme is presented as its corner stone. The other features of our service are as follows: simple key management without the need of key derivation for users to decrypt cipher texts, composing attributes for accessing resources with subject attributes´ having inner structures, and authorization relatively separating from encryption. We also give some proofs and analysis of our implementation.
  • Keywords
    authorisation; cloud computing; cryptography; digital storage; outsourcing; PDP; PEP; Policy Decision Point; Policy Enforcement Point; access control; attribute-full proxy re-encryption scheme; cryptography; data outsourcing; data owner; flexibility requirement; public cloud storage; sensitive information protection; service outsourcing; service-oriented technologies; simple key management; Authorization; Cloud computing; Encryption; Public key; Access Control; Attribute-based Encryption Scheme; Outsourced Data Service; Proxy Re-encryption Scheme;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems Workshops (ICDCSW), 2012 32nd International Conference on
  • Conference_Location
    Macau
  • ISSN
    1545-0678
  • Print_ISBN
    978-1-4673-1423-7
  • Type

    conf

  • DOI
    10.1109/ICDCSW.2012.65
  • Filename
    6258201