DocumentCode
720548
Title
CloudSky: A Controllable Data Self-Destruction System for Untrusted Cloud Storage Networks
Author
Lingfang Zeng ; Yang Wang ; Dan Feng
fYear
2015
fDate
4-7 May 2015
Firstpage
352
Lastpage
361
Abstract
In cloud services, users may frequently be required to reveal their personal private information which could be stored in the cloud to used by different parts for different purposes. However, in a cloud-wide storage network, the servers are easily under strong attacks and also commonly experience software/hardware faults. As such, the private information could be under great risk in such an untrusted environment. Given that the presented personal sensitive information is usually out of user´s controlin most cloud-based services, ensuring data security and privacy protection with respect to untrusted storage network has become a formidable challenge in research. To address these challenges, in this paper we propose a self-destruction system, named CloudSky, which is able to enforce the security of user privacy over the untrusted cloud in a controllable way. CloudSky exploits a key control mechanism based on the attribute-based encryption (ABE) and takes advantage of active storage networks to allow the user to control the subjective life-cycle and the access control polices of the private data whose integrity is ensured by using HMAC to cope with untrusted environments. %and thereby adapting it to the cloud in terms of both performance and security requirements. The feasibility of the system in terms of its performance and scalability is demonstrated by experiments on a real large-scale storage network.
Keywords
authorisation; cloud computing; data integrity; data protection; private key cryptography; trusted computing; ABE; CloudSky; HMAC; access control polices; active storage networks; attribute-based encryption; cloud services; cloud-based services; cloud-wide storage network; controllable data self-destruction system; data security; hardware faults; key control mechanism; large-scale storage network; performance analysis; personal private information; personal sensitive information; privacy protection; private data integrity; scalability analysis; software faults; strong attacks; subjective life-cycle control; untrusted cloud storage networks; Access control; Cloud computing; Data privacy; Encryption; Servers; attribute-based encryption; cloud storage network; data privacy; data self-destruction;
fLanguage
English
Publisher
ieee
Conference_Titel
Cluster, Cloud and Grid Computing (CCGrid), 2015 15th IEEE/ACM International Symposium on
Conference_Location
Shenzhen
Type
conf
DOI
10.1109/CCGrid.2015.12
Filename
7152501
Link To Document