Back to Search Start Over

Privacy Enhanced Access Control for Outsourced Data Sharing

Authors :
Steven M. Bellovin
Mariana Raykova
Hang Zhao
Source :
Financial Cryptography and Data Security ISBN: 9783642329456, Financial Cryptography
Publication Year :
2012
Publisher :
Springer Berlin Heidelberg, 2012.

Abstract

Traditional access control models often assume that the entity enforcing access control policies is also the owner of data and resources. This assumption no longer holds when data is outsourced to a third-party storage provider, such as the cloud. Existing access control solutions mainly focus on preserving confidentiality of stored data from unauthorized access and the storage provider. However, in this setting, access control policies as well as users’ access patterns also become privacy sensitive information that should be protected from the cloud. We propose a two-level access control scheme that combines coarse-grained access control enforced at the cloud, which provides acceptable communication overhead and at the same time limits the information that the cloud learns from his partial view of the access rules and the access patterns, and fine-grained cryptographic access control enforced at the user’s side, which provides the desired expressiveness of the access control policies. Our solution handles both read and write access control.

Details

ISBN :
978-3-642-32945-6
ISBNs :
9783642329456
Database :
OpenAIRE
Journal :
Financial Cryptography and Data Security ISBN: 9783642329456, Financial Cryptography
Accession number :
edsair.doi...........7117ad665978797dd86bece86f4705f6
Full Text :
https://doi.org/10.1007/978-3-642-32946-3_17