4.7 Article

CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage

Journal

IEEE TRANSACTIONS ON SERVICES COMPUTING
Volume 14, Issue 1, Pages 111-124

Publisher

IEEE COMPUTER SOC
DOI: 10.1109/TSC.2018.2791538

Keywords

Secure cloud storage; ciphertext-policy attribute-based encryption; access credentials misuse; traceability and revocation; auditing

Funding

  1. National Research Foundation, Prime Minister's Office, Singapore, under its Corporate Laboratory@University Scheme, National University of Singapore
  2. Singapore Telecommunications Ltd.
  3. National Natural Science Foundation of China [61632012, 61672239, 61402282]
  4. Shanghai high technology field project [16511101400]
  5. NSFCZhejiang Joint Fund for the Integration of Industrialization and Informatization [U1509219]
  6. Shanghai Youth Talent Development Program [14YF1410400]
  7. Shanghai Ocean University Science and Technology Development Program
  8. EPSRC [EP/R006938/1] Funding Source: UKRI

Ask authors/readers for more resources

Secure cloud storage is a new cloud service designed to protect the confidentiality of outsourced data and provide flexible data access to cloud users. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is considered a promising technique for securing the service, but it may lead to security breaches due to the misuse of access credentials. This paper investigates cases of access credential misuse and proposes a novel cloud storage system CryptCloud(+) to mitigate such issues. Additionally, security analysis and experiments are presented to demonstrate the system's utility.
Secure cloud storage, which is an emerging cloud service, is designed to protect the confidentiality of outsourced data but also to provide flexible data access for cloud users whose data is out of physical control. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is regarded as one of the most promising techniques that may be leveraged to secure the guarantee of the service. However, the use of CP-ABE may yield an inevitable security breach which is known as the misuse of access credential (i.e., decryption rights), due to the intrinsic all-or-nothing decryption feature of CP-ABE. In this paper, we investigate the two main cases of access credential misuse: one is on the semi-trusted authority side, and the other is on the side of cloud user. To mitigate the misuse, we propose the first accountable authority and revocable CP-ABE based cloud storage system with white-box traceability and auditing, referred to as CryptCloud(+). We also present the security analysis and further demonstrate the utility of our system via experiments.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available