Revocable and Efficient Blockchain-Based Fine-Grained Access Control Against EDoS Attacks in Cloud Storage

被引:1
作者
Zhang, Qingyang [1 ,2 ]
Xu, Chang [1 ,2 ]
Zhong, Hong [1 ,2 ]
Gu, Chengjie [3 ,4 ]
Cui, Jie [1 ,2 ]
机构
[1] Anhui Univ, Sch Comp Sci & Technol, Key Lab Intelligent Comp & Signal Proc, Minist Educ, Hefei 230039, Peoples R China
[2] Anhui Univ, Anhui Engn Lab IoT Secur Technol, Hefei 230039, Peoples R China
[3] Anhui Univ Sci & Technol, Sch Publ Secur & Emergency Management, Hefei 231131, Peoples R China
[4] Secur Res Inst, New Grp H3C, Hefei 230088, Peoples R China
基金
中国国家自然科学基金;
关键词
Cloud computing; Blockchains; Security; Servers; Access control; Encryption; Industrial Internet of Things; ciphertext-policy attributed-based encryption; cloud storage service; EDoS attacks; blockchain; ATTRIBUTE-BASED ENCRYPTION; SECURITY; SYSTEM;
D O I
10.1109/TC.2024.3398502
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Users have become accustomed to storing data on the cloud using ciphertext policy attribute-based encryption (CP-ABE) for fine-grained access control. However, this encryption method does not consider the ability of malicious users to launch thousands of file download requests when launching an economic denial of sustainability attack (EDoS), which may be more expensive for data owners. Existing solutions typically use a cloud server to verify the download permissions of the data users. However, cloud servers are not completely trusted and cloud server providers and colluding data users can still launch an EDoS attack. With our scheme, using CP-ABE, a blockchain is introduced for verifying the download permission of data users. In addition, we propose a new mechanism to solve the problem of malicious user revocations under EDoS attacks by updating the ciphertext and symmetric encryption technology. A formal security proof has demonstrated that the proposed scheme is suitable for plaintext attack security. Theoretical and experimental analyses show that our scheme performs more efficiently than previous methods.
引用
收藏
页码:2012 / 2024
页数:13
相关论文
共 33 条
  • [1] FAME: Fast Attribute-based Message Encryption
    Agrawal, Shashank
    Chase, Melissa
    [J]. CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, : 665 - 682
  • [2] Expressive ciphertext-policy attribute-based encryption with direct user revocation
    Bai C.
    Zhang Y.
    Ma H.
    Liu Z.
    [J]. International Journal of Embedded Systems, 2017, 9 (06) : 495 - 504
  • [3] A revocable attribute based data sharing scheme resilient to DoS attacks in smart grid
    Bayat, Majid
    Arkian, Hamid Reza
    Aref, Mohammad Reza
    [J]. WIRELESS NETWORKS, 2015, 21 (03) : 871 - 881
  • [4] Improved Dual System ABE in Prime-Order Groups via Predicate Encodings
    Chen, Jie
    Gay, Romain
    Wee, Hoeteck
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2015, PT II, 2015, 9057 : 595 - 624
  • [5] Server-Aided Revocable Attribute-Based Encryption
    Cui, Hui
    Deng, Robert H.
    Li, Yingjiu
    Qin, Baodong
    [J]. COMPUTER SECURITY - ESORICS 2016, PT II, 2016, 9879 : 570 - 587
  • [6] A Practical and Efficient Bidirectional Access Control Scheme for Cloud-Edge Data Sharing
    Cui, Jie
    Li, Bei
    Zhong, Hong
    Min, Geyong
    Xu, Yan
    Liu, Lu
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2022, 33 (02) : 476 - 488
  • [7] A Novel Attribute-Based Access Control Scheme Using Blockchain for IoT
    Ding, Sheng
    Cao, Jin
    Li, Chen
    Fan, Kai
    Li, Hui
    [J]. IEEE ACCESS, 2019, 7 : 38431 - 38441
  • [8] Arbitrary-State Attribute-Based Encryption with Dynamic Membership
    Fan, Chun-I
    Huang, Vincent Shi-Ming
    Ruan, He-Ming
    [J]. IEEE TRANSACTIONS ON COMPUTERS, 2014, 63 (08) : 1951 - 1961
  • [9] Revocable Attribute-Based Encryption With Data Integrity in Clouds
    Ge, Chunpeng
    Susilo, Willy
    Baek, Joonsang
    Liu, Zhe
    Xia, Jinyue
    Fang, Liming
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (05) : 2864 - 2872
  • [10] Goyal V., 2006, IACR Cryptology ePrint Archive, DOI [10.1145/1180405.1180418, 10.1145/1180405., DOI 10.1145/1180405.1180418]