DocumentCode
49848
Title
A Secure Data Self-Destructing Scheme in Cloud Computing
Author
Jinbo Xiong ; Ximeng Liu ; Zhiqiang Yao ; Jianfeng Ma ; Qi Li ; Kui Geng ; Chen, Patrick S.
Author_Institution
Fac. of Software, Fujian Normal Univ., Fuzhou, China
Volume
2
Issue
4
fYear
2014
fDate
Oct.-Dec. 1 2014
Firstpage
448
Lastpage
458
Abstract
With the rapid development of versatile cloud services, it becomes increasingly susceptible to use cloud services to share data in a friend circle in the cloud computing environment. Since it is not feasible to implement full lifecycle privacy security, access control becomes a challenging task, especially when we share sensitive data on cloud servers. In order to tackle this problem, we propose a key-policy attribute-based encryption with time-specified attributes (KP-TSABE), a novel secure data self-destructing scheme in cloud computing. In the KP-TSABE scheme, every ciphertext is labeled with a time interval while private key is associated with a time instant. The ciphertext can only be decrypted if both the time instant is in the allowed time interval and the attributes associated with the ciphertext satisfy the key´s access structure. The KP-TSABE is able to solve some important security problems by supporting user-defined authorization period and by providing fine-grained access control during the period. The sensitive data will be securely self-destructed after a user-specified expiration time. The KP-TSABE scheme is proved to be secure under the decision l-bilinear Diffie-Hellman inversion (l-Expanded BDHI) assumption. Comprehensive comparisons of the security properties indicate that the KP-TSABE scheme proposed by us satisfies the security requirements and is superior to other existing schemes.
Keywords
authorisation; cloud computing; data privacy; inverse problems; public key cryptography; access control; cloud computing environment; data self-destructing scheme security; decision l-bilinear Diffie-Hellman inversion; key-policy attribute-based encryption with time-specified attribute KP-TSABE; l-expanded BDHI assumption; lifecycle privacy security; user-defined authorization period; Authorization; Cloud computing; Computer security; Data privacy; Encryption; Sensitive data; assured deletion; cloud computing; fine-grained access control; privacy-preserving; secure self-destructing;
fLanguage
English
Journal_Title
Cloud Computing, IEEE Transactions on
Publisher
ieee
ISSN
2168-7161
Type
jour
DOI
10.1109/TCC.2014.2372758
Filename
6963363
Link To Document