To store a massive amount of data and to handle huge traffic; generally, many applications or software are deployed on the cloud. Nowadays every application/software is generating data and security of this data also plays a vital role. But when data is transferred from local systems to cloud, that is, when information is getting transferred over the network, data is vulnerable (any attacker can quickly attack data). An attacker can easily read and write data that is being transferred over the network, if the data is not encrypted. Even though the data is encoded, an assailant may attempt to decode the message/data by obtaining the key through a brute-force attack. Moreover, it is not always the case that the attacker is an external threat; sometimes, the attacker can be an insider, such as a staff personnel working in the same organization. In such instances, an authorized user may try to access data for which they have no privilege to get access to information that is transferred over the network, which is dynamic access of data (access of data that is transferring over the web). In this paper, a solution to the issues is presented in detail. To thwart the attacker from decrypting the key, we must re-encrypt the text using a new key. Furthermore, re-encryption must occur promptly upon detecting any malicious activity. If an authenticated user attempts to access data beyond their pleasure, the manager can then restrict/block that user.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Revoking Dynamic Access with Enforced Encryption

  • B. V. Ramana,
  • N. Thirupathi Rao,
  • Debnath Bhattacharyya

摘要

To store a massive amount of data and to handle huge traffic; generally, many applications or software are deployed on the cloud. Nowadays every application/software is generating data and security of this data also plays a vital role. But when data is transferred from local systems to cloud, that is, when information is getting transferred over the network, data is vulnerable (any attacker can quickly attack data). An attacker can easily read and write data that is being transferred over the network, if the data is not encrypted. Even though the data is encoded, an assailant may attempt to decode the message/data by obtaining the key through a brute-force attack. Moreover, it is not always the case that the attacker is an external threat; sometimes, the attacker can be an insider, such as a staff personnel working in the same organization. In such instances, an authorized user may try to access data for which they have no privilege to get access to information that is transferred over the network, which is dynamic access of data (access of data that is transferring over the web). In this paper, a solution to the issues is presented in detail. To thwart the attacker from decrypting the key, we must re-encrypt the text using a new key. Furthermore, re-encryption must occur promptly upon detecting any malicious activity. If an authenticated user attempts to access data beyond their pleasure, the manager can then restrict/block that user.