Yuan Zhai , Haochen Yang , Jingyu Yao , Tao Wang , Yanwei Zhou , Feng Zhu , Bo Yang
{"title":"DRAC:一种动态的细粒度访问控制方案,用于具有审查强制阻力的云存储","authors":"Yuan Zhai , Haochen Yang , Jingyu Yao , Tao Wang , Yanwei Zhou , Feng Zhu , Bo Yang","doi":"10.1016/j.jisa.2025.104123","DOIUrl":null,"url":null,"abstract":"<div><div>The increasing reliance on cloud storage for data outsourcing raises concerns regarding the security and access to sensitive information and private data. To ensure the security of cloud data, encryption technology is widely applied in cloud storage. However, most existing encryption schemes rely on the assumption that encryption keys remain private, which may become invalid under censorship by unauthorized authorities, potentially leading to data leaks in the cloud. Furthermore, accessing and sharing data in the cloud are crucial for its utilization, and enabling authorized users to achieve fine-grained access control during the dynamic sharing of cloud data poses a significant challenge. To address these issues, this paper proposes a novel fine-grained access control scheme, DRAC. By combining deniable encryption primitives with ciphertext-policy attribute-based encryption technology that supports revocation, the proposed scheme achieves: (1) provide privacy protection for cloud data; (2) resist censorship by unauthorized authorities; and (3) support dynamic fine-grained access control for cloud data. The security and correctness of DRAC are analyzed theoretically, while its performance is evaluated experimentally. The results demonstrate that the system is feasible and effective in practical applications.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"93 ","pages":"Article 104123"},"PeriodicalIF":3.8000,"publicationDate":"2025-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"DRAC: A dynamic fine-grained access control scheme for cloud storage with censorship-coerced resistance\",\"authors\":\"Yuan Zhai , Haochen Yang , Jingyu Yao , Tao Wang , Yanwei Zhou , Feng Zhu , Bo Yang\",\"doi\":\"10.1016/j.jisa.2025.104123\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The increasing reliance on cloud storage for data outsourcing raises concerns regarding the security and access to sensitive information and private data. To ensure the security of cloud data, encryption technology is widely applied in cloud storage. However, most existing encryption schemes rely on the assumption that encryption keys remain private, which may become invalid under censorship by unauthorized authorities, potentially leading to data leaks in the cloud. Furthermore, accessing and sharing data in the cloud are crucial for its utilization, and enabling authorized users to achieve fine-grained access control during the dynamic sharing of cloud data poses a significant challenge. To address these issues, this paper proposes a novel fine-grained access control scheme, DRAC. By combining deniable encryption primitives with ciphertext-policy attribute-based encryption technology that supports revocation, the proposed scheme achieves: (1) provide privacy protection for cloud data; (2) resist censorship by unauthorized authorities; and (3) support dynamic fine-grained access control for cloud data. The security and correctness of DRAC are analyzed theoretically, while its performance is evaluated experimentally. The results demonstrate that the system is feasible and effective in practical applications.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"93 \",\"pages\":\"Article 104123\"},\"PeriodicalIF\":3.8000,\"publicationDate\":\"2025-06-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212625001607\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625001607","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
DRAC: A dynamic fine-grained access control scheme for cloud storage with censorship-coerced resistance
The increasing reliance on cloud storage for data outsourcing raises concerns regarding the security and access to sensitive information and private data. To ensure the security of cloud data, encryption technology is widely applied in cloud storage. However, most existing encryption schemes rely on the assumption that encryption keys remain private, which may become invalid under censorship by unauthorized authorities, potentially leading to data leaks in the cloud. Furthermore, accessing and sharing data in the cloud are crucial for its utilization, and enabling authorized users to achieve fine-grained access control during the dynamic sharing of cloud data poses a significant challenge. To address these issues, this paper proposes a novel fine-grained access control scheme, DRAC. By combining deniable encryption primitives with ciphertext-policy attribute-based encryption technology that supports revocation, the proposed scheme achieves: (1) provide privacy protection for cloud data; (2) resist censorship by unauthorized authorities; and (3) support dynamic fine-grained access control for cloud data. The security and correctness of DRAC are analyzed theoretically, while its performance is evaluated experimentally. The results demonstrate that the system is feasible and effective in practical applications.
期刊介绍:
Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.