Journal of Frontiers of Computer Science and Technology ›› 2020, Vol. 14 ›› Issue (11): 1865-1878.DOI: 10.3778/j.issn.1673-9418.1911020

Multi-authority Access Control Scheme in Cloud Environment

ZHENG Lianghan, HE Heng, TONG Qian, YANG Xiang, CHEN Xiang   

  1. 1. College of Computer Science and Technology, Wuhan University of Science and Technology, Wuhan 430065, China
    2. Hubei Province Key Laboratory of Intelligent Information Processing and Real-Time Industrial System, Wuhan University of Science and Technology, Wuhan 430065, China
  Online:2020-11-01 Published:2020-11-09



  1. 1. 武汉科技大学 计算机科学与技术学院,武汉 430065
    2. 武汉科技大学 湖北省智能信息处理与实时工业系统重点实验室,武汉 430065


Ciphertext-policy attribute-based encryption (CP-ABE) is very suitable for data access control in cloud environment. The existing CP-ABE algorithm does not consider that the access structure of multiple files has a hierarchical relationship, and it needs to encrypt each file to realize its access control requirements, which leads to large costs. In addition, most schemes only have a single authorized institution to manage the key, which has high requirements on the computing power and honesty of the authorized institution. This paper proposes a cloud data access control scheme based on blockchain with multi-authority (BMAC). In BMAC, this paper designs a hierarchical CP-ABE algorithm, for multiple data files with hierarchical access structure, one encryption only, then visitors can decrypt part of the files when meeting some access conditions and get all files when meeting all conditions. This paper also designs a multi-authority key management method based on blockchain, which enables all authorized institutions to distribute private keys honestly and concurrently through blockchain technology. Performance and security analysis show that BMAC can effectively protect data confidentiality, resist collusion attack, achieve secure and efficient fine-grained data access control and decentralized private key distribution.

Key words: cloud computing, access control, attribute-based encryption, multi-authority, blockchain



关键词: 云计算, 访问控制, 属性加密, 多授权机构, 区块链