• DocumentCode
    38584
  • Title

    Expressive, Efficient, and Revocable Data Access Control for Multi-Authority Cloud Storage

  • Author

    Kan Yang ; Xiaohua Jia

  • Author_Institution
    Dept. of Comput. Sci., City Univ. of Hong Kong, Kowloon, China
  • Volume
    25
  • Issue
    7
  • fYear
    2014
  • fDate
    Jul-14
  • Firstpage
    1735
  • Lastpage
    1744
  • Abstract
    Data access control is an effective way to ensure the data security in the cloud. Due to data outsourcing and untrusted cloud servers, the data access control becomes a challenging issue in cloud storage systems. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is regarded as one of the most suitable technologies for data access control in cloud storage, because it gives data owners more direct control on access policies. However, it is difficult to directly apply existing CP-ABE schemes to data access control for cloud storage systems because of the attribute revocation problem. In this paper, we design an expressive, efficient and revocable data access control scheme for multi-authority cloud storage systems, where there are multiple authorities co-exist and each authority is able to issue attributes independently. Specifically, we propose a revocable multi-authority CP-ABE scheme, and apply it as the underlying techniques to design the data access control scheme. Our attribute revocation method can efficiently achieve both forward security and backward security. The analysis and simulation results show that our proposed data access control scheme is secure in the random oracle model and is more efficient than previous works.
  • Keywords
    authorisation; cloud computing; cryptography; access policies; attribute revocation problem; backward security; ciphertext-policy attribute-based encryption; data outsourcing; data security; forward security; multiauthority cloud storage systems; revocable data access control; revocable multiauthority CP-ABE scheme; untrusted cloud servers; Access control; Cloud computing; Encryption; Public key; Servers; Access control; CP-ABE; attribute revocation; cloud storage; multi-authority;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2013.253
  • Filename
    6620875