Title :
Fine-grained document sharing using attribute-based encryption in cloud servers
Author :
Dongyang Xu ; Fengying Luo ; Lin Gao ; Zhi Tang
Author_Institution :
Inf. Security Res. Center, China Electron. Stand. Inst., Beijing, China
Abstract :
With the rapid development of cloud computing, more and more users begin to share documents in cloud servers. Since cloud servers are not within the trusted domain of users, encryption and access control are needed to protect the digital content. Attribute-based encryption is a favorable scheme that has been used for content protection in cloud computing. It can provide “one-to-many” encryption service so that one encrypted file can be decrypted by multiple prospective recipients whose attributes conform to the access policy. Currently, all existing attribute-based encryption schemes assume that the digital content and authorized users are equally privileged; however, there are emerging application scenarios that demand digital content and users with different privileges. In this paper, we present a new attribute-based encryption scheme that can generate security keys of different class for users by integrating ciphertext-policy attribute-based encryption and hierarchical cryptographic key management. Thus, we achieve the fine-grained document sharing which means that users can preview the same document with different privileges. We use hierarchical keys derived from a chain of one-way functions. Extensive analysis shows that our proposed scheme is simple, efficient and secure. The proposed scheme can provide “one-fits-many” encryption service.
Keywords :
authorisation; cloud computing; document handling; public key cryptography; trusted computing; access control; access policy; attribute-based encryption schemes; authorized users; ciphertext-policy attribute-based encryption; cloud computing; cloud servers; content protection; digital content; encrypted file; fine-grained document sharing; hierarchical cryptographic key management; one-fits-many encryption service; one-to-many encryption service; one-way functions; security keys; trusted user domain; Access control; Cloud computing; Encryption; Public key; Servers; Attribute-based encryption; access control; cloud computing; document sharing; key management;
Conference_Titel :
Innovative Computing Technology (INTECH), 2013 Third International Conference on
Conference_Location :
London
Print_ISBN :
978-1-4799-0047-3
DOI :
10.1109/INTECH.2013.6653703