跳到主要导航 跳到搜索 跳到主要内容

Who is touching my cloud

  • Hua Deng
  • , Qianhong Wu
  • , Bo Qin*
  • , Jian Mao
  • , Xiao Liu
  • , Lei Zhang
  • , Wenchang Shi
  • *此作品的通讯作者
  • Wuhan University
  • Beihang University
  • School of Information
  • Academy of Satellite Application

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Advanced access controls have been proposed to secure sensitive data maintained by a third party. A subtle issue in such systems is that some access credentials may be leaked due to various reasons, which could severely damage data security. In this paper, we investigate leakage tracing enabled access control over outsourced data, so that one can revoke the suspected leaked credentials or prepare judicial evidences for legal procedure if necessary. Specifically, we propose a leaked access credential tracing (LACT) framework to secure data outsourced to clouds and formalize its security model. Following the framework, we construct a concrete LACT scheme that is provably secure. The proposed scheme offers fine-grained access control over outsourced data, by which the data owner can specify an access policy to ensure that the data is only accessible to the users meeting the policy. In case of suspectable illegal access to outsourced data with leaked credentials, a tracing procedure can be invoked to tracing in a black-box manner at least one of the users who leaked their access credentials. The tracing procedure can run without the cloud service provider being disturbed. Analysis shows that the introduction of tracing access credential leakage incurs little additional cost to either data outsourcing or access procedure.

源语言英语
主期刊名Computer Security, ESORICS 2014 - 19th European Symposium on Research in Compter Security, Proceedings
出版商Springer Verlag
362-379
页数18
版本PART 1
ISBN(印刷版)9783319112022
DOI
出版状态已出版 - 2014
活动19th European Symposium on Research in Computer Security, ESORICS 2014 - Wroclaw, 波兰
期限: 7 9月 201411 9月 2014

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
编号PART 1
8712 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议19th European Symposium on Research in Computer Security, ESORICS 2014
国家/地区波兰
Wroclaw
时期7/09/1411/09/14

指纹

探究 'Who is touching my cloud' 的科研主题。它们共同构成独一无二的指纹。

引用此