Journal on Communications ›› 2016, Vol. 37 ›› Issue (1): 88-99.doi: 10.11959/j.issn.1000-436x.2016010

• Academic paper • Previous Articles     Next Articles

Multi-user collaborative access control scheme in cloud storage

li SHIJiao1,2,he HUANGChuan1,Jing WANG1,yu QINKuang1,3,Kai HE1   

  1. 1 Computer School, Wuhan University, Wuhan 430072, China
    2 School of Information Science and Technology,Jiujiang University, Jiujiang 332005,China
    3 School of Information and Communication,Guilin University of Electronic Technology, Guilin 541004, China
  • Online:2016-01-25 Published:2016-01-27
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China;The Ph.D. Programs Founda-tion of Ministry of Education of China

Abstract:

CP-ABE was considered as one of most suitable methods of access control in cloud storage. However, it was just fit for reading or modifying different data files respectively. When CP-ABE was applied directly to data access collaborative control by multiple users, there would be such problems as data being modified disorderly.When multiple users access collaboratively the data stored on the cloud, legitimate users should modify the same ciphertext file orderly on the premise of confidentiality and collusion-resistance and the copies of ciphertext file should be generated as few as possible. Two multi-user collaborative access control schemes MCA-F and MCA-B for the file and its logical blocks each were proposed. The MCA-F scheme meets the requirement of access control in which the minimal granularity of control is a single data file. In MCA-F scheme, hierarchical encryption is adopted,a part of decrypting computation is transferred to a cloud server to decrease the computational cost on users when decrypting.In allusion to the simultaneous write-data access control of multiple users, a method is designed to manage semi-stored modified data submitted by menders. The MCA-B scheme is used for the access control in which a logical block of the file is the minimal granularity of control. This scheme designs a mechanism of logical blocking of the file and a representing method based on index matrix, and the representation of sub data mask is put forward to describe write permission of multiple users on different logical blocks of the same file. MCA-B scheme supports the dynamic change of the structure of logical blocks of the file, and the owners or menders do not need to be online always. Compared with the existing schemes, not only do proposed schemes provide multi-user collaborative access control in cloud storage, but also the client storage of reading access control and the computation of encrypting and decrypting are both lesser.

Key words: cloud storage, access control, attribute-based encryption, multi-user collaborative access

No Suggested Reading articles found!