您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 销售管理 > 基于属性群的云存储密文访问控制方案
(730070)CryptographicAccessControlSchemeinCloudStorageBasedonAttributeGroupYANGXiao-dong,WANGCai-fen(CollegeofMathematicsandInformationScience,NorthwestNormalUniversity,Lanzhou730070,China)AbstractThispaperproposesacryptographicaccesscontrolschemebasedonattributegroupincloudstorage.ThesymmetriccryptosystemisusedtoencrypttheoriginaldatabytheDataOwner(DO),andtheattribute-basedencryptionalgorithmisusedtoencryptthesymmetrickey.DOdelegatethetaskofdatare-encryptiontotheCloudServiceProvider(CSP),whichnotonlyreducesthecomputationalcostofDO,butalsodoesnotrevealextrainformationoftheplaintexttoCSP.Theproposedschemesupportstheunitofacollectionofmultipleuserswhenanyattributeoruserisrevoked.Thefine-grainedandflexibleaccesscontrolcanbeachievedbyhybridcryptosystemmeachanism.Comparedwiththeexistingaccesscontrolschemes,theproposedschemeismoreefficientinrevocationcostandcanalleviatetheadministeringburdersonDO.Theschemeguaranteescollusionresistanceagainstcolludingusers,dataconfidentiality,forwardandbackwardsecrecy.Keywordscryptographicaccesscontrol;cloudstorage;attributegroup;userrevocation;re-encryptionDOI:10.3969/j.issn.1000-3428.2012.11.007ComputerEngineering3811Vol.38No.1120126June201210003428(2012)11002003ATP309.71(DataOwner,DO)(Ciphertext-policyAttribute-basedEncryption,CP-ABE)[1]CP-ABECP-ABECP-ABEDO(CloudServiceProvider,CSP)CP-ABE[2]CP-ABEDO[3]DOCSP[4-5]2DODO[6]CP-ABECP-ABE2CP-ABE(AES)ManagerDOCSP(61163038)(NWNU-LKQN-10-22)(1981)2011-12-14E-maily200888@163.com381121CSP2.1CA2p1G2G112:eGGGg1G12{,,,}q(1)iiq1iwG()iattii12{,,,}nUuuuiUUiCA*,pZ12{,,PKGG1,,(,),{}}qiiggeggw(,)MKg2.22(1)UtuUtSKCA*prZ(r)i*iprZtu()/(,:rtiiSKDgD'()(),)iiirrrattigwDgCAtSKtuiiUManager1u2u3u4u12{,}234{,,}13{,}12{,,34,}CA12341134{,,}Uuuu2124{,,}Uuuu3234{,,}Uuuu424{,}UuuManager(2)Manager(KEK)Ujv*jpKEKZtututPKManagertPKtuUManagerKEK11234567{,,,,,,}Uuuuuuuu1u11248{,,,}PKKEKKEKKEKKEK1KEK2.3DOffkEfkf()ffkCEfTxkTxx1xkxq*psZR(0)Rqsx(0)xq()(())parentxqindexx()parentxx()indexxxYTDOfk(0)(0)'()(,(,),,:,())yyyssfqqyyattCTTCkeggCgyYCgCwDO(,)fCCTCSP2.4Manager(,)fCCTCT(1)yYyU*ypKZyU'(0)(0)'()(,(,),,:,(()))yyyyssfKqqyyattCTTCkeggCgyYCgCw(2)KEKiUiU()iKEKU11134{,,}UuuuKEK1u3u4u{5,8}vv1U1()KEKU58{,}KEKKEK1U1()KEKU(3)E()(:{()})yyKKKEKUHdryYEK(4)ManagerServer'(,,)fHdrCCT2.5fHdr'CTfkfCf(1)tuCSPfManagertuServer'(,,)fHdrCCT(2)tuHdrtuitu()iKEKKEKUtPKHdriUiK11134{,,}Uuuu1U1()KEKU58{,}KEKKEK1u11{,PKKEK248,,}KEKKEKKEK4u4125{,,,PKKEKKEKKEK11}KEK1u181()KEKKEKUPK4u154()KEKKEKUPKHdr1U1Ktu1/()/'()(,:(),())iiiiKrrrrtiiattiSKDgDgwDg(3)tu'CTTy22201265(0)()(0)1/'''(0)()((),)(,)(,),(,)(,,)((),(()))yiyyyyyyiyqrrattrqyyytKKqryyattegwgeDCegguUeDCDecryptNodeCTSKyegwotherwisexx{}jzxjkjz'(,,)jzjFDecryptNodeCTSKz(0)(,)zjrqeggxkjzFLagrangexF(0)(,)xrqeggR'(,,)ADecryptNodeCTSKR(0)(,)(,)RrqrseggeggtuT/((,)/)fkCeCDA(4)tufkfCf2.6CACSPiUi(i)Manager(1)'*psZ'*ipKZiU'iiKKManager''''''''()()(0)(0)'()(0)(0)'()(,(,),,,(()),\{}:,(()))iiiiyyyyssssfKqsqsiiattKqsqsyyattCTTCkeggCgCgCwyYiCgCwiU(2)KEKiUiU()iKEKU13u1114{,}UuuKEK1u4u811{,}vv1U1811(){,}KEKUKEKKEK1()KEKU3u1u4u1()KEKUManager'()()({()},\{}:{()})iyiyKKKEKUKKKEKUHdrEKyYiEK31fCfkDOfkManager'CTfkCP-ABET(,)seggfkiiUiKHdrAESAESCP-ABE[1]2T(,)rseggTr()()iirriattDgwx(0)(,)xrqegg(,)rsegg'CTfk3Managers'siUiK'iK's(,)seggi'()(,)sseggiU'iKiK's'()(,)sseggi(,)segg4VmwareWorkstationRedHatEnterpriseLinux6.21GBcpabe-0.11[7]openssl-1.0.0[8]192AES521MB10MB50MB322DOCSPDO[5]DODO[6]DOCP-ABE(26)262012656ICCS-PWLoadRunner1072h7(a)(b)75000.1s1~22~34ICCS-PWICCS-PW[1].[EB/OL].[2011-08-01].[2].[M].:,2011.[3]BuyyaR,CheeShin-Yeo,VenugopaS.Market-orientedCloudComputing:Vision,Hype,andRealityforDeliveringITServicesasComputingUtilities[C]//Proc.ofHPCC’08.Dalian,China:[s.n.],2008.[4].[EB/OL].(2011-01-15).=2590507188137.[5]![EB/OL].[2011-08-01].[6]Seamicro.SM1000DataSheet[EB/OL].[2011-08-01].[7]CGI1.2Specification[EB/OL].[2011-08-01].[8].SQLite[EB/OL].[2011-08-01].~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~(22)5[1]BethencourtJ,SahaiA,WatersB.Ciphertext-policyAttribute-basedEncryption[C]//Proc.ofSSP’07.California,USA:[s.n.],2007.[2]IbraimiL,AsimM,PetkovicM.AnEncryptionSchemeforaSecurePolicyUpdating[C]//Proc.ofSECRYPT’10.Athens,Greece:[s.n.],2010.[3]YuShucheng,WangCong,RenKui,etal.AttributeBasedDataSharingwithAttributeRevocation[C]//Proc.ofASIACCS’10.Beijing,China:[s.n.],2010.[4]HongCheng,ZhangMin,Fe
本文标题:基于属性群的云存储密文访问控制方案
链接地址:https://www.777doc.com/doc-3224435 .html