TY - GEN
T1 - RWAC
T2 - 2018 IEEE Symposium on Computers and Communications, ISCC 2018
AU - Wang, Jinmiao
AU - Lang, Bo
AU - Zhu, Ruijin
N1 - Publisher Copyright:
© 2018 IEEE.
PY - 2018/11/15
Y1 - 2018/11/15
N2 - With the development of the Internet and personal digital devices, self-organizing and open-pattern collaborations are becoming popular. In such environments, data are usually outsourced to third-party servers in the cloud, which are out of the control domain of data owners. Hence, traditional access control models, which are enforced relying on data storage servers, will face new security challenges. In this paper, we propose a self-contained read and write access control (RWAC) scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and attribute-based group signature (ABGS) mechanism. By adopting a two-step encryption strategy using CP-ABE and utilizing the write control policy as the signature policy in ABGS, RWAC ensures that fine-grained read and write access control can be enforced during decryption and signature generation without dependence on any third parties. To prevent privacy leakage from RWAC policies, we adopt a CP-ABE scheme with hidden policy. Then, we introduce the policy hiding method into ABGS and propose an ABGS scheme with hidden policy. Moreover, users can trace the edit history of each data object with the signature or a write list. The security analysis indicates that RWAC is able to enforce fine-grained read and write access controls for group collaborations while also ensuring data confidentiality and integrity.
AB - With the development of the Internet and personal digital devices, self-organizing and open-pattern collaborations are becoming popular. In such environments, data are usually outsourced to third-party servers in the cloud, which are out of the control domain of data owners. Hence, traditional access control models, which are enforced relying on data storage servers, will face new security challenges. In this paper, we propose a self-contained read and write access control (RWAC) scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and attribute-based group signature (ABGS) mechanism. By adopting a two-step encryption strategy using CP-ABE and utilizing the write control policy as the signature policy in ABGS, RWAC ensures that fine-grained read and write access control can be enforced during decryption and signature generation without dependence on any third parties. To prevent privacy leakage from RWAC policies, we adopt a CP-ABE scheme with hidden policy. Then, we introduce the policy hiding method into ABGS and propose an ABGS scheme with hidden policy. Moreover, users can trace the edit history of each data object with the signature or a write list. The security analysis indicates that RWAC is able to enforce fine-grained read and write access controls for group collaborations while also ensuring data confidentiality and integrity.
KW - attribute-based encryption
KW - attribute-based group signature
KW - group collaboration
KW - read control
KW - write control
UR - https://www.scopus.com/pages/publications/85059213184
U2 - 10.1109/ISCC.2018.8538611
DO - 10.1109/ISCC.2018.8538611
M3 - 会议稿件
AN - SCOPUS:85059213184
T3 - Proceedings - IEEE Symposium on Computers and Communications
SP - 97
EP - 103
BT - 2018 IEEE Symposium on Computers and Communications, ISCC 2018
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 25 June 2018 through 28 June 2018
ER -