Back to Search
Start Over
Privacy Preserving Delegated Access Control in Public Clouds
- Source :
- Cyber Center Publications
- Publication Year :
- 2014
- Publisher :
- Purdue University, 2014.
-
Abstract
- Current approaches to enforce fine-grained access control on confidential data hosted in the cloud are based on fine-grained encryption of the data. Under such approaches, data owners are in charge of encrypting the data before uploading them on the cloud and re-encrypting the data whenever user credentials change. Data owners thus incur high communication and computation costs. A better approach should delegate the enforcement of fine-grained access control to the cloud, so to minimize the overhead at the data owners, while assuring data confidentiality from the cloud. We propose an approach, based on two layers of encryption, that addresses such requirement. Under our approach, the data owner performs a coarse-grained encryption, whereas the cloud performs a fine-grained encryption on top of the owner encrypted data. A challenging issue is how to decompose access control policies (ACPs) such that the two layer encryption can be performed. We show that this problem is NP-complete and propose novel optimization algorithms. We utilize an efficient group key management scheme that supports expressive ACPs. Our system assures the confidentiality of the data and preserves the privacy of users from the cloud while delegating most of the access control enforcement to the cloud.
- Subjects :
- Delegate
Computer science
media_common.quotation_subject
Data_MISCELLANEOUS
Cloud computing
Access control
Computer security
computer.software_genre
Encryption
Upload
Engineering
Medicine and Health Sciences
Physical Sciences and Mathematics
Overhead (computing)
identity
encryption
media_common
Delegation
business.industry
cloud computing
access control
Client-side encryption
Life Sciences
Computer Science Applications
Computational Theory and Mathematics
Privacy
40-bit encryption
policy decomposition
On-the-fly encryption
business
computer
Information Systems
Computer network
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Cyber Center Publications
- Accession number :
- edsair.doi.dedup.....844789c0a20126edce0ea8fe20129ca7
- Full Text :
- https://doi.org/10.1109/TKDE.2013.68