Title :
Secure Cloud Storage: A framework for Data Protection as a Service in the multi-cloud environment
Author :
Quang Hieu Vu;Maurizio Colombo;Rasool Asal;Ali Sajjad;Fadi Ali El-Moussa;Theo Dimitrakos
Author_Institution :
Etisalat BT Innovation Center (EBTIC), Khalifa University, United Arab Emirates
Abstract :
This paper introduces Secure Cloud Storage (SCS), a framework for Data Protection as a Service (DPaaS) to cloud computing users. Compared to the existing Data Encryption as a Service (DEaaS) such as those provided by Amazon and Google, DPaaS provides more flexibility to protect data in the cloud. In addition to supporting the basic data encryption capability as DEaaS does, DPaaS allows users to define fine-grained access control policies to protect their data. Once data is put under an access control policy, it is automatically encrypted and only if the policy is satisfied, the data could be decrypted and accessed by either the data owner or anyone else specified in the policy. The key idea of the SCS framework is to separate data management from security management in addition to defining a full cycle of data security automation from encryption to decryption. As a proof-of-concept for the design, we implemented a prototype of the SCS framework that works with both BT Cloud Compute platform and Amazon EC2. Experiments on the prototype have proved the efficiency of the SCS framework.
Keywords :
"Cloud computing","Encryption","Access control","Data protection"
Conference_Titel :
Communications and Network Security (CNS), 2015 IEEE Conference on
DOI :
10.1109/CNS.2015.7346879