This document proposes a two-factor validation control framework for online distributed services. Specifically, it implements an attribute-based access control framework that requires both a customer secret key and a lightweight security device. This two-factor authentication mechanism enhances security, especially when multiple customers share the same computer. It also allows fine-grained access control based on user attributes while preserving privacy, as the cloud server only knows that a user satisfies certain attributes, not their identity. A simulation is performed to demonstrate the feasibility of the proposed two-factor framework.