2010 · 87 citations · 12 references
Secure ServiceEngineeringInformation SecurityData-centric SecurityIdentity ManagementSecure Data AccessAccess ControlData ManagementData PrivacyCloud Computing SecurityComputer ScienceKey ManagementData SecurityCryptographyEncryptionCloud ComputingCloud CryptographyBlockchainAccess Control Technique
Data security and access control in cloud computing is a major challenge because users outsource sensitive data, and existing purely cryptographic solutions impose heavy computational overhead for key distribution and management. The paper proposes a capability‑based access control technique to ensure that only authorized users can access outsourced data. The approach employs capability‑based access control together with a modified Diffie‑Hellman key exchange to securely share a symmetric key between the cloud provider and the user, reducing key distribution overhead. Simulations demonstrate that the proposed method is highly efficient and secure under current security models.
Data security and access control is one of the most challenging ongoing research work in cloud computing, because of users outsourcing their sensitive data to cloud providers. Existing solutions that use pure cryptographic techniques to mitigate these security and access control problems suffer from heavy computational overhead on the data owner as well as the cloud service provider for key distribution and management. This paper addresses this challenging open problem using capability based access control technique that ensures only valid users will access the outsourced data. This work also proposes a modified Diffie-Hellman key exchange protocol between cloud service provider and the user for secretly sharing a symmetric key for secure data access that alleviates the problem of key distribution and management at cloud service provider. The simulation run and analysis shows that the proposed approach is highly efficient and secure under existing security models.
12
Above the Clouds: A Berkeley View of Cloud Computing
Michael Armbrust, Armando Fox, Rean Griffith et al. · UC Berkeley · 2009 · 5.7K citations
Luis M. Vaquero, Luis Rodero‐Merino, Juan Cáceres et al. · ACM SIGCOMM Computer Communication Review · 2008 · 2.6K citations · Full text
Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
Shucheng Yu, Cong Wang, Kui Ren et al. · 2010 · 1.6K citations
Engineering, Information Security, Data-centric Security +16