A Secure and Efficient Data Sharing Framework with Delegated Capabilities in Hybrid Cloud

Xuejiao Liu, Yingjie Xia, Yang Xiang, M. Hassan, Abdulhameed Alelaiwi
{"title":"A Secure and Efficient Data Sharing Framework with Delegated Capabilities in Hybrid Cloud","authors":"Xuejiao Liu, Yingjie Xia, Yang Xiang, M. Hassan, Abdulhameed Alelaiwi","doi":"10.1109/SocialSec2015.13","DOIUrl":null,"url":null,"abstract":"Hybrid cloud is a widely used cloud architecture in large companies that can outsource data to the public cloud, while still supporting various clients like mobile devices. However, such public cloud data outsourcing raises serious security concerns, such as how to preserve data confidentiality and how to regulate access policies to the data stored in public cloud. To address this issue, we design a hybrid cloud architecture that supports data sharing securely and efficiently, even with resource-limited devices, where private cloud serves as a gateway between the public cloud and the data user. Under such architecture, we propose an improved construction of attribute-based encryption that has the capability of delegating encryption/decryption computation, which achieves flexible access control in the cloud and privacy-preserving in datautilization even with mobile devices. Extensive experiments show the scheme can further decrease the computational cost and space overhead at the user side, which is quite efficient for the user with limited mobile devices. In the process of delegating most of the encryption/decryption computation to private cloud, the user can not disclose any information to the private cloud. We also consider the communication securitythat once frequent attribute revocation happens, our scheme is able to resist some attacks between private cloud and data user by employing anonymous key agreement.","PeriodicalId":121098,"journal":{"name":"2015 International Symposium on Security and Privacy in Social Networks and Big Data (SocialSec)","volume":"48 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-11-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 International Symposium on Security and Privacy in Social Networks and Big Data (SocialSec)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SocialSec2015.13","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Hybrid cloud is a widely used cloud architecture in large companies that can outsource data to the public cloud, while still supporting various clients like mobile devices. However, such public cloud data outsourcing raises serious security concerns, such as how to preserve data confidentiality and how to regulate access policies to the data stored in public cloud. To address this issue, we design a hybrid cloud architecture that supports data sharing securely and efficiently, even with resource-limited devices, where private cloud serves as a gateway between the public cloud and the data user. Under such architecture, we propose an improved construction of attribute-based encryption that has the capability of delegating encryption/decryption computation, which achieves flexible access control in the cloud and privacy-preserving in datautilization even with mobile devices. Extensive experiments show the scheme can further decrease the computational cost and space overhead at the user side, which is quite efficient for the user with limited mobile devices. In the process of delegating most of the encryption/decryption computation to private cloud, the user can not disclose any information to the private cloud. We also consider the communication securitythat once frequent attribute revocation happens, our scheme is able to resist some attacks between private cloud and data user by employing anonymous key agreement.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
混合云中具有委派功能的安全高效数据共享框架
混合云是大公司中广泛使用的云架构,它可以将数据外包到公共云,同时仍然支持各种客户端,如移动设备。然而,这种公有云数据外包引发了严重的安全问题,例如如何保持数据机密性以及如何规范对公有云存储数据的访问策略。为了解决这个问题,我们设计了一种混合云架构,即使在资源有限的设备上也能安全有效地支持数据共享,其中私有云充当公共云和数据用户之间的网关。在此架构下,我们提出了一种改进的基于属性的加密结构,该结构具有委托加/解密计算的能力,在云中实现了灵活的访问控制,即使在移动设备上也能实现数据化的隐私保护。大量的实验表明,该方案可以进一步降低用户端的计算成本和空间开销,对于移动设备有限的用户来说是非常有效的。在将大部分加/解密计算委托给私有云的过程中,用户不能向私有云泄露任何信息。我们还考虑了通信安全性,一旦发生频繁的属性撤销,我们的方案可以通过采用匿名密钥协议抵御私有云和数据用户之间的一些攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
QoSC: A QoS-Aware Storage Cloud Based on HDFS A Novel Robust Image-Hashing Method for Content Authentication Enhanced Twitter Sentiment Analysis by Using Feature Selection and Combination Efficient and Secure Data Retrieval Scheme Using Searchable Encryption in Cloud Storage Insecurity of Anonymous Login with German Personal Identity Cards
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1