• DocumentCode
    39421
  • Title

    Privacy Preserving Delegated Access Control in Public Clouds

  • Author

    Nabeel, Mohamed ; Bertino, Elisa

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
  • Volume
    26
  • Issue
    9
  • fYear
    2014
  • fDate
    Sept. 2014
  • Firstpage
    2268
  • Lastpage
    2280
  • Abstract
    Current approaches to enforce fine-grained access control on confidential data hosted in the cloud are based on fine-grained encryption of the data. Under such approaches, data owners are in charge of encrypting the data before uploading them on the cloud and re-encrypting the data whenever user credentials change. Data owners thus incur high communication and computation costs. A better approach should delegate the enforcement of fine-grained access control to the cloud, so to minimize the overhead at the data owners, while assuring data confidentiality from the cloud. We propose an approach, based on two layers of encryption, that addresses such requirement. Under our approach, the data owner performs a coarse-grained encryption, whereas the cloud performs a fine-grained encryption on top of the owner encrypted data. A challenging issue is how to decompose access control policies (ACPs) such that the two layer encryption can be performed. We show that this problem is NP-complete and propose novel optimization algorithms. We utilize an efficient group key management scheme that supports expressive ACPs. Our system assures the confidentiality of the data and preserves the privacy of users from the cloud while delegating most of the access control enforcement to the cloud.
  • Keywords
    authorisation; cloud computing; cryptography; data privacy; NP-complete problem; coarse-grained encryption; data confidentiality; fine-grained encryption; group key management scheme; optimization algorithms; privacy preserving delegated access control; public clouds; Access control; Cloud computing; Encryption; Privacy; Protocols; Privacy; access control; cloud computing; encryption; identity; policy decomposition;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2013.68
  • Filename
    6509875