• DocumentCode
    2845449
  • Title

    A Secure Fine-Grained Access Control Mechanism for Networked Storage Systems

  • Author

    Lin, Hsiao-Ying ; Kubiatowicz, John ; Tzeng, Wen-Guey

  • Author_Institution
    Intell. Inf. & Commun. Res. Center, Nat. Chiao Tung Univ., Hsinchu, Taiwan
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    225
  • Lastpage
    234
  • Abstract
    Networked storage systems provide storage services for users over networks. Secure networked storage systems store encrypted data to guarantee data confidentiality. However, using encryption schemes somehow restricts the access control function over stored data. We address the access control function for a secure networked storage system by proposing a fine-grained access control mechanism. In our mechanism, a user cannot only read or write data but also grant the reading permissions of a single file or a whole directory of files to others with low cost. Moreover, these functions are supported in a confidential way against honest-but-curious storage servers. Our technical contribution is to propose a hybrid encryption scheme for a typical structure of a file system by integrating a hierarchical proxy re-encryption scheme and a hierarchical key assignment scheme. We measure the computation overhead for reading, writing, and granting operations by experiments. Our experimental results show that getting a finer access control mechanism does not cost much.
  • Keywords
    authorisation; cryptography; data privacy; digital storage; data confidentiality; encrypted data; encryption schemes; hierarchical key assignment scheme; hierarchical proxy re-encryption scheme; honest-but-curious storage servers; hybrid encryption scheme; secure fine-grained access control mechanism; secure networked storage systems; technical contribution; Access control; Encryption; Games; Public key; Servers; Networked storage system; access control mechanism; hybrid encryption; proxy re-encryption;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on
  • Conference_Location
    Gaithersburg, MD
  • Print_ISBN
    978-1-4673-2067-2
  • Type

    conf

  • DOI
    10.1109/SERE.2012.35
  • Filename
    6258312