4.7 Article

SecRBAC: Secure data in the Clouds

Journal

IEEE TRANSACTIONS ON SERVICES COMPUTING
Volume 10, Issue 5, Pages 726-740

Publisher

IEEE COMPUTER SOC
DOI: 10.1109/TSC.2016.2553668

Keywords

cloud computing; authorization; Data-centric security; role-based access control

Funding

  1. European Commission 7th Framework Programme (FP7-ICT) under the project Interoperable Trust Assurance Infrastructure (INTER-TRUST - ICT FP7) [317731]
  2. European Commission Horizon Programme under the project Framework for Self-Organized Network Management in Virtualized and Software Defined Networks [SELFNET - H2020-ICT-2014-2/671672]

Ask authors/readers for more resources

Most current security solutions are based on perimeter security. However, Cloud computing breaks the organization perimeters. When data resides in the Cloud, they reside outside the organizational bounds. This leads users to a loos of control over their data and raises reasonable security concerns that slow down the adoption of Cloud computing. Is the Cloud service provider accessing the data? Is it legitimately applying the access control policy defined by the user? This paper presents a data-centric access control solution with enriched role-based expressiveness in which security is focused on protecting user data regardless the Cloud service provider that holds it. Novel identity-based and proxy re-encryption techniques are used to protect the authorization model. Data is encrypted and authorization rules are cryptographically protected to preserve user data against the service provider access or misbehavior. The authorization model provides high expressiveness with role hierarchy and resource hierarchy support. The solution takes advantage of the logic formalism provided by Semantic Web technologies, which enables advanced rule management like semantic conflict detection. A proof of concept implementation has been developed and a working prototypical deployment of the proposal has been integrated within Google services.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available