Authors:
Sana Belguith
1
;
Nesrine Kaaniche
2
;
Abderrazak Jemai
3
;
Maryline Laurent
2
and
Rabah Attia
1
Affiliations:
1
Tunisia Polytechnic School, Laboratory of Electronic Systems and Communication Network, Telnet Holding and Telnet Innovation Labs, Tunisia
;
2
University Paris-Saclay, France
;
3
University of Sciences of Tunis, Tunisia
Keyword(s):
Cloud Storage Systems, Attribute-based Encryption, Attribute-based Signature, Data Confidentiality, Privacy.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Applied Cryptography
;
Cryptographic Techniques and Key Management
;
Data Engineering
;
Databases and Data Security
;
Information and Systems Security
;
Internet Technology
;
Security and Privacy in the Cloud
;
Web Information Systems and Technologies
Abstract:
Several existing access control solutions mainly focus on preserving confidentiality of stored data from unauthorized
access and the storage provider. Moreover, to keep sensitive user data confidential against untrusted
servers, existing solutions usually apply cryptographic methods by disclosing data decryption keys only to authorized
users. However, these solutions inevitably introduce a heavy computation overhead on the data owner
for key distribution and data management when fine-grained data access control is desired. In addition, access
control policies as well as users’ access patterns are also considered as sensitive information that should be
protected from the cloud. In this paper, we propose PAbAC, a novel privacy preserving Attribute-based framework,
that combines attribute-based encryption and attribute-based signature mechanisms for securely sharing
outsourced data via the public cloud. Our proposal is multifold. First, it ensures fine-grained cryptographic access
contr
ol enforced at the data owner’s side, while providing the desired expressiveness of the access control
policies. Second, PAbAC preserves users’ privacy, while hiding any identifying information used to satisfy
the access control. Third, PAbAC is proven to be highly scalable and efficient for sharing outsourced data in
remote servers, at both the client and the cloud provider side.
(More)