SCAuth: Selective Cloud User Authorization for Ciphertext-Policy Attribute-Based Access Control
Nazatul Haque Sultan, Ferdous Ahmed Barbhuiya, Nityananda Sarma · 2017
Cloud storage service allows its users to outsource and share data in a cloud environment. To achieve data privacy along with access control, cryptographic mechanisms are used. Ciphertext-policy attribute-based encryption (CP-ABE) is a widely used cryptographic mechanism, which facilitates data privacy and access control over encrypted data. Any user, having a qualified access right, can gain access to the data. As the cloud is a dynamic environment, sometimes it may need to allow only a few users, from the set of users having qualified access rights, to access the data. However, access right revocation or user revocation, in CP-ABE, is a tedious and costly event. This paper proposes the first CP-ABE based access control scheme, named as SCAuth in short, which allows selected users, from the set of users having sufficient access rights, to gain access to the data. It neither requires user revocation nor re-encryption of the data using a fresh access policy. The security analysis has been done using Information Theory Tools and it establishes that the proposed scheme is unconditionally secure and collusion resistant.