DocumentCode :
570255
Title :
Privacy preserving delegated access control in the storage as a service model
Author :
Nabeel, Mohamed ; Bertino, Elisa
Author_Institution :
Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
fYear :
2012
fDate :
8-10 Aug. 2012
Firstpage :
645
Lastpage :
652
Abstract :
Current approaches for enforcing fine-grained access control and confidentiality to sensitive data hosted in the cloud are based on selectively encrypting the data before uploading it to the cloud. In such an approach, organizations have to enforce authorization policies through encryption. They thus incur high communication and computation cost to manage keys and encryptions whenever user credentials or organizational authorization policies change. Ideally, organizations should use encryption only in order to hide the data from the cloud, whereas the cloud should be in charge of enforcing authorization policies on the hidden data in order to minimize the overhead at organizations. In this paper, we propose a novel approach for delegating privacy-preserving fine-grained access enforcement to the cloud. Our approach is based on a recent key management scheme that allows users whose attributes satisfy a certain policy to derive the data encryption keys only for the content they are allowed to access from the cloud. Our approach preserves the confidentiality of the data and the user privacy from the cloud, while delegating most of the access control enforcement to the cloud. Further, in order to reduce the cost of re-encryption required whenever the access control policies changes, our approach uses incremental encryption techniques.
Keywords :
authorisation; cloud computing; cryptography; data privacy; organisational aspects; cloud hosted data; data encryption keys; fine-grained access control; incremental encryption techniques; organizational authorization policies; privacy preserving delegated access control; privacy-preserving fine-grained access enforcement; reencryption cost; sensitive data confidentiality; storage-as-a-service model; user credentials; user privacy; Access control; Cascading style sheets; Cryptography; Data privacy; Privacy; Registers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Reuse and Integration (IRI), 2012 IEEE 13th International Conference on
Conference_Location :
Las Vegas, NV
Print_ISBN :
978-1-4673-2282-9
Electronic_ISBN :
978-1-4673-2283-6
Type :
conf
DOI :
10.1109/IRI.2012.6303070
Filename :
6303070
Link To Document :
بازگشت