Nowadays, more and more users outsource their data to third party cloud storage servers for the purpose of sharing, so cloud data sharing becomes one of the popular services offered by cloud service providers. However, the third party storage servers in cloud data sharing systems, which are not fully trusted by data owners, make access control to the shared data a challenging issue. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is an emerging cryptographic solution for this issue, dealing with dynamic changes to users' access privileges (attribute revocation) in its practical applications as cloud data sharing systems is a real challenge. To overcome this challenge, we propose a fine-grained access control scheme for cloud data sharing systems by designing secure and efficient attribute-revocable CP-ABE scheme. Our scheme only allows non-revoked users in the attribute group to update their secret key by themselves using their unique key-update keys and the ciphertexts are updated by minimally trusted cloud server using a ciphertext-update key. Compared with the existing access controls achieved by attribute-revocable CP-ABE schemes, our proposed access control scheme reduces the trust degree of the cloud server in the attribute revocation mechanism. Furthermore, the analysis indicates that our access control scheme is more secure and efficient to apply to practical scenarios.
목차
Abstract 1. Introduction 2. Preliminaries 2.1. Access Structure 2.2. Lagrange Interpolation 2.3. Shamir Secret Sharing Scheme 2.4. Bilinear Maps 2.5. Decisional Bilinear Diffie-Hellman (DBDH) Assumption. 3. Definitions and Models 3.1. System Model 3.2. Algorithm Definitions 3.3. Security Model and Security Requirements 4. Access Control by Secure and Efficient Attribute-Revocable CPABE 4.1. Scheme Overview 4.2. Scheme Construction 4.3. Correctness 5. Analysis of Our Proposed Access Control 5.1. Comprehensive Analysis 5.2. Security Analysis 5.3. Performance Analysis 6. Conclusion References
키워드
Access controlattributes revocationciphertext-policy attribute-based encryptionand cloud data sharing
저자
Nyamsuren Vaanchig [ School of Information and Software Engineering, University of Electronic Science and Technology of China ]
Corresponding Author
Wei Chen [ School of Information and Software Engineering, University of Electronic Science and Technology of China ]
Zhiguang Qin [ School of Information and Software Engineering, University of Electronic Science and Technology of China ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.10 No.10