This document proposes a new decentralized access control scheme for secure data storage in clouds that supports anonymous authentication. The key points are:
1) It allows for multiple key distribution centers (KDCs) so the architecture is decentralized. This prevents any single point of failure.
2) It provides anonymous authentication of users storing data in the cloud so their identity is protected from the cloud.
3) Only authorized users with valid attributes can access data, so it enables fine-grained and distributed access control. The scheme is resilient against replay and collusion attacks.