ADAPTIVE SECURE DOCUMENT ACCESS MECHANISM IN
CLOUD
ABSTRACT
The project “Adaptive Secure document Access Mechanism in
Cloud” is enables to provide the security in remote accessing. When we
consider the Software Company, the Centralized Cloud Server helps the
users to access information from anywhere through remote devices like
Laptop, Personal PC, Mobile etc.., While using the server mechanism there
is a chance of sharing of the secret details. In order to avoid this problem
there is a need for implementation of certain restrictions to various
individuals in the company according to their roles or grade. With the help
of the centralized remote server mechanism one can access the details in
various places through their login authentication but here there is no security
for handling the secure document. In this case we propose an adaptive secure
access mechanism for remote service we can provide the security for all the
information located on the cloud.
INTRODUCTION
Many access control models have been proposed over the years in the
literature. In this context, role-based access control (RBAC) is a well-known
access control model which can help to simplify security management
especially in large-scale systems. In the RBE scheme proposed in the paper
the users management can be decentralized to individual roles; that is the
administrators only manage the roles and the relationship among them while
the roles have the flexibility in specifying the user memberships themselves.
The proposed trust models address the missing aspect of trust in
cryptographic RBAC schemes to secure data storage in the cloud, and can
provide better protection of stored data than using cryptographic approaches
alone. The paper has proposed trust models for owners and roles in RBAC
systems which are using cryptographic RBAC schemes to secure stored
data.
LITERATURE SURVEY
[Link] Title Author Merits Demerits
1. A Trust and Context Fujun Feng, It extends Privacy issue in
Based Access Chuang Lin, the traditional location
Control Model for Dongsheng Peng1, RBAC model information
Distributed Systems Junshan Li with the notion of when capturing
trust and context. the context
information.
2. Trust Based Access [Link] and The New user is based
Control Scheme for [Link] trustworthiness only on
Pervasive of the user and recommender list.
Computing the
Environment recommender are
formulated using
fuzzy set and
fuzzy logic.
3. Trusted Access Fan Yue-qin and Access control The deficiency of
Control Model Based Zhang Yong-sheng based on task and the article is that
on Role and Task in role. It can the reputation
Cloud Computing control the user's value of
interview times calculation is not
by judging the specific enough.
number of
reputation value.
4. Integrating Trust with Lan Zhou, Vijay Allow the data Need to enhance
Cryptographic Role- Varadharajan, owners to use the the quality of
based Access Control Michael Hitchens trust evaluation decision making
for Secure Cloud to decide whether by data owners of
Data Storage or not to store the cloud storage
their encrypted service.
data in the cloud
for a
particular role.
5. Provably Secure Yan Zhu and Gail- Revocation It only supports
Role-Based Jo on Ahn mechanism based fully collusion
Encryption with on partial-order security under a
Revocation key hierarchy special case.
Mechanism with respect to
the public key
infrastructure
6. Cryptographic SELIM G. AKL Highly placed in Need of hierarchy
Solution to a and PETER D. the hierarchy to is represented by
Problem of TAYLOR store a large partial order set.
Access Control in a number of
Hierarchy cryptographic
keys
7. A Data Outsourcing Sabrina De An approach for Need to
Architecture Capitani di enforcing integration with
Combining Vimercati authorization the Web
Cryptography and Sara Foresti policies and paradigm.
Access Control Sushil Jajodia supporting
Stefano Paraboschi dynamic
Pierangela authorizations.
Samarati
8 Achieving Secure, Shucheng Yu, It defines and Data
Scalable, and Fine- Cong enforce access confidentiality,
grained Data Wang,KuiRen , policies based and scalability
Access Control in and Wenjing Lou on data attributes, simultaneously,
Cloud Computing and, allow the which is not
data owner to provided by
delegate the current work.
computation
tasks to control
untrusted cloud
servers.
9 Role Based Access Carlo Bellettini, Authorizations Still relevant
Control Models Elisa Bertino and can become application
Elena Ferrari extremely large. requirements not
addressed by
current
RBAC models and
mechanisms.
10 Trust Relationships R. Yahalom and Enables Need of more
in Secure Systems - B. Klein Th. Beth verifying that the authentication
A Distributed assumptions on steps and
Authentication which the trust protocols.
Perspective requirements.
EXISTING SYSTEM
In a typical service-oriented computing, the server defines some
functions including the implementation, the parameters, and the interfaces. If
a user wants to use the remote service, she calls one of the functions by
following the function interface. After the server finishes the task of the
function, the result will be sent back to the user. In the following context, we
use function and service interchangeably. The existing works control the
access privileges of a user depending on his or her roles. For security the
system generate OTP to the user which is not secured. In existing user level
security is not able to protect the sensitive secured document on the
organization.
DRAW BACKS
In existing user level security is not able to protect the sensitive
secured document on the organization.
It lacks in Remote service authentication
It does not support remote access security by accessing information
using remote access devices like mobile, Laptop, PDA’s.
It does not providing high level security.
PROPOSED SYSTEM
The proposed model provides trust models for owners and roles in
RBAC systems which are using cryptographic RBAC schemes to
secure stored data. RBAC simplifies the security management is large
scale system, RBE decentralizes the user management to individual
roles. The proposed trust models take into account role inheritance
and hierarchy in the evaluation of trustworthiness of roles. The
proposed trust models address the trust in cryptographic RBAC
schemes using role and context based approach. It constrains what a
user can do, as well as what programs executing on behalf of the users
are allowed to do.
ADVANTAGES OF PROPOSED SYSTEM
It provides high level security for accessing document through remote
access device.
It Provides security in remote access through various factor like Role,
Time, Device used and location.
High Accuracy
Easy to maintain and less cost consumption
CONCLUSION
In this way the access control module seeks to prevent the activity that
could lead to breach of security. With the support of RBAC and
cryptographic algorithm, we able to do the access control [Link]
system consider many aspects of user for accessing the secured file.
REFERENCES
[1] D. F. Ferraiolo and D. R. Kuhn, “Role-based access controls,” in Proc.
15th NIST-NCSC Nat. Comput. Secur. Conf., Oct. 1992, pp. 554–563.
[2] S. D. C. di Vimercati, S. Foresti, S. Jajodia, S. Paraboschi,
and P. Samarati, “A data outsourcing architecture combining
cryptography and access control,” in Proc. CSAW, Nov. 2007,
pp. 63–69.
[3] S. D. C. D. Vimercati, S. Foresti, S. Jajodia, S. Paraboschi, and
P. Samarati, “Over-encryption: Management of access control evolution
on outsourced data,” in Proc. VLDB, Sep. 2007, pp. 123–134.
[4] S. Yu, C. Wang, K. Ren, and W. Lou, “Achieving secure, scalable, and
fine-grained data access control in cloud computing,” in Proc. IEEE
INFOCOM, Mar. 2010, pp. 1–9.
[5] Y. Zhu, H.-X. Hu, G.-J. Ahn, H.-X. Wang, and S.-B. Wang, “Provably
secure role-based encryption with revocation mechanism,” J. Comput.
Sci. Technol., vol. 26, no. 4, pp. 697–710, Jul. 2011.
[6] L. Zhou, V. Varadharajan, and M. Hitchens, “Enforcing role-based
access control for secure data storage in the cloud,” Comput. J., vol. 54,
no. 10, pp. 1675–1687, Oct. 2011.
[7] S. Chakraborty and I. Ray, “TrustBAC: Integrating trust relationships
into the RBAC model for access control in open systems,” in Proc.
SACMAT, Jun. 2006, pp. 49–58.
[8] F. Feng, C. Lin, D. Peng, and J. Li, “A trust and context based access
control model for distributed systems,” in Proc. HPCC, Sep. 2008,
pp. 629–634.
[9] M. Toahchoodee, R. Abdunabi, I. Ray, and I. Ray, “A trust-based access
control model for pervasive computing applications,” in Proc. DBSec,
vol. 5645., Jul. 2009, pp. 307–314.
[10] R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman,
“Role-based access control models,” IEEE Comput., vol. 29, no. 2,
pp. 38–47, Feb. 1996.
[11] R. Sandhu, D. Ferraiolo, and D. Kuhn, “The NIST model for rolebased
access control: Towards a unified standard,” in Proc. RBAC, 2000,
pp. 47–63.
[12] S. G. Akl and P. D. Taylor, “Cryptographic solution to a problem of
access control in a hierarchy,” ACM Trans. Comput. Syst., vol. 1, no. 3,
pp. 239–248, Aug. 1983.
[13] M. Blaze, J. Feigenbaum, and J. Lacy, “Decentralized trust
management,” in Proc. IEEE Symp. Secur. Privacy, May 1996,
pp. 164–173.