A Hybrid Multi-Cloud Framework Using the IBBE Key Management System for Securing Data Storage

被引:5
作者
Sohal, Manreet [1 ]
Bharany, Salil [2 ]
Sharma, Sandeep [2 ]
Maashi, Mashael S. [3 ]
Aljebreen, Mohammed [4 ]
机构
[1] Guru Nanak Dev Engn Coll, Dept Comp Applicat, Ludhiana 141006, Punjab, India
[2] Guru Nanak Dev Univ, Dept Comp Engn & Technol, Amritsar 143005, Punjab, India
[3] King Saud Univ, Coll Comp & Informat Sci, Software Engn Dept, Riyadh 11451, Saudi Arabia
[4] King Saud Univ, Community Coll, Dept Comp Sci, Riyadh 11437, Saudi Arabia
关键词
multi-clouds; storage security; client-side cryptography; key management; BROADCAST ENCRYPTION;
D O I
10.3390/su142013561
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Information storage and access in multi-cloud environments have become quite prevalent. In this paper, a multi-cloud framework is presented that secures users' data. The primary goal of this framework is to secure users' data from untrusted Cloud Service Providers (CSPs). They can collude with other malicious users and can hand over users' data to these malicious users for their beneficial interests. In order to achieve this goal, the data are split into parts, and then each part is encrypted and uploaded to a different cloud. Therefore, client-side cryptography is used in this framework. For encrypting users' data, the BDNA encryption technique is used. This framework presents a hybrid cryptographic approach that uses Identity-based Broadcast Encryption (IBBE) for managing the keys of the symmetric key algorithm (BDNA) by encrypting them with the particular version of IBBE. The work presented in this research paper is the first practical implementation of IBBE for securing encryption keys. Earlier, IBBE was only used for securely broadcasting data across many users over a network. The security of this hybrid scheme was proved through Indistinguishable Chosen-Ciphertext Attacks. This double encryption process makes the framework secure against all insiders and malicious users' attacks. The proposed framework was implemented as a web application, and real-time storage clouds were used for storing the data. The workflow of the proposed framework is presented through screenshots of different working modules.
引用
收藏
页数:24
相关论文
共 44 条
  • [11] Identity-based encryption from the Weil pairing
    Boneh, D
    Franklin, M
    [J]. SIAM JOURNAL ON COMPUTING, 2003, 32 (03) : 586 - 615
  • [12] Bowers KD, 2009, CCS'09: PROCEEDINGS OF THE 16TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, P187
  • [13] Cachin Christian, 2009, SIGACT News, V40, P81, DOI 10.1145/1556154.1556173
  • [14] Delerablée C, 2007, LECT NOTES COMPUT SC, V4833, P200
  • [15] Derfouf M, 2015, 2015 INTERNATIONAL CONFERENCE ON CLOUD TECHNOLOGIES AND APPLICATIONS (CLOUDTECH 15), P295
  • [16] Collaborative and secure sharing of healthcare data in multi-clouds
    Fabian, Benjamin
    Ermakova, Tatiana
    Junghanns, Philipp
    [J]. INFORMATION SYSTEMS, 2015, 48 : 132 - 150
  • [17] Halevy D, 2002, LECT NOTES COMPUT SC, V2442, P47
  • [18] Anonymous Identity-Based Broadcast Encryption with Chosen-Ciphertext Security
    He, Kai
    Weng, Jian
    Liu, Jia-Nan
    Liu, Joseph K.
    Liu, Wei
    Deng, Robert H.
    [J]. ASIA CCS'16: PROCEEDINGS OF THE 11TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 247 - 255
  • [19] Privacy-preserving identity-based broadcast encryption
    Hur, Junbeom
    Park, Chanil
    Hwang, Seong Oun
    [J]. INFORMATION FUSION, 2012, 13 (04) : 296 - 303
  • [20] Indhumathi AT, 2017, 2017 THIRD INTERNATIONAL CONFERENCE ON SCIENCE TECHNOLOGY ENGINEERING & MANAGEMENT (ICONSTEM), P347, DOI 10.1109/ICONSTEM.2017.8261307