
Privacy Protection Based Access Control Scheme in Cloud-Based Services
Abstract
Cloud-Based services have become a hot topic with rapid development of computer technology. Not only do they provide convenience for users, they also bring many security issues, such as data sharing and privacy issues. We present an access control system with privilege separation based on privacy protection (PS-ACS) in this Privacy Protection based Access Control Scheme in Cloud-based Services paper. We logically divide users in the PS-ACS scheme into private domain (PRD) and public domain (PUD).
Privacy Protection based Access Control Scheme in Cloud-Based Services In PRD, we adopt the Key-Aggregate Encryption (KAE) and the Improved Attribute-based Signature (IABS) respectively to achieve read access permission and write access permission. In PUD, we are building a new multi-authority ciphertext policy attribute-based encryption (CP-ABE) scheme with efficient decryption to avoid the issues of single point failure and complicated key distribution, and designing an efficient attribute revocation method for it.
Advantages
- In this paper, we present a more systematic, flexible and efficient access control scheme.
- We provide a thorough analysis of security and complexity of our proposed PS-ACS scheme. The functionality and simulation results provide data security in acceptable performance impact, and prove the feasibility of the scheme.
- The evaluation results show the high efficiency of our scheme.