首页> 外文会议>2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Hierarchical Attribute-Based Access Control with Authentication for Outsourced Data in Cloud Computing
【24h】

Hierarchical Attribute-Based Access Control with Authentication for Outsourced Data in Cloud Computing

机译:云计算中基于身份的基于属性的分层访问控制对外包数据的访问

获取原文
获取原文并翻译 | 示例

摘要

Access control is one of the most important security mechanisms in cloud computing. Attributed based encryption provides an approach that allows data owners to integrate data access policies within the encrypted data. However, little work has been done to explore flexible authorization in specifying the data user's privileges and enforcing the data owner's policy in cloud based environments. In this paper, we propose a hierarchical attribute based access control scheme by extending ciphertext-policy attribute-based encryption (CP-ABE) with a hierarchical structure of multiauthorities and exploiting attribute-based signature (ABS). The proposed scheme not only achieves scalability due to its hierarchical structure, but also inherits fine-grained access control with authentication in supporting write privilege on outsourced data in cloud computing. In addition, we decouple the task of policy management from security enforcement by using the extensible access control markup language (XACML) framework. Extensive analysis shows that our scheme is both efficient and scalable in dealing with access control for outsourced data in cloud computing.
机译:访问控制是云计算中最重要的安全机制之一。基于属性的加密提供了一种允许数据所有者将数据访问策略集成到加密数据中的方法。但是,在基于云的环境中,在指定数据用户的特权并执行数据所有者的策略方面,几乎没有开展任何工作来探索灵活的授权。在本文中,我们通过扩展具有多个权限的分层结构的密文策略基于属性的加密(CP-ABE)并利用基于属性的签名(ABS),提出了一种基于分层属性的访问控制方案。所提出的方案不仅由于其分层结构而实现了可伸缩性,而且还继承了带有身份验证的细粒度访问控制,以支持对云计算中外包数据的写特权。此外,我们通过使用可扩展的访问控制标记语言(XACML)框架将策略管理的任务与安全实施脱钩。大量分析表明,我们的方案在处理云计算中对外包数据的访问控制时既高效又可扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号