...
首页> 外文期刊>Future generation computer systems >A secure and efficient Internet of Things cloud encryption scheme with forensics investigation compatibility based on identity-based encryption
【24h】

A secure and efficient Internet of Things cloud encryption scheme with forensics investigation compatibility based on identity-based encryption

机译:一种安全有效的内容云加密方案,基于基于身份的加密,具有取证调查兼容性的云加密方案

获取原文
获取原文并翻译 | 示例
           

摘要

Data security is a challenge for end-users of cloud services as the users have no control over their data once it is transmitted to the cloud. A potentially corrupt cloud service provider can obtain the end-users' data. Conventional PKI-based solutions are insufficient for large-scale cloud systems, considering efficiency, scalability, and security. In large-scale cloud systems, the key management requirements include scalable encryption, authentication, and non-repudiation services, as well as the ability to share files with different users and data recovery when the user keys of encrypted data are not accessible. Further requirements in cloud systems include the ability to provide the means for digital forensic investigations on encrypted data. Once data on the cloud is encrypted with a user's key it becomes impossible to access by forensic investigation teams. In this regard, distributing the trust of key management into multiple authorities is desirable. In the literature, there is no available secure cloud storage system with secure and efficient Type-3 pairings, supporting Encryption-as-a-Service (EaaS) and multiple Public Key Generators (PKGs). This paper proposes an efficient Identity-based cryptography (IBC) architecture for secure cloud storage, named Secure Cloud Storage System (SCSS), which supports distributed key management and encryption mechanisms and support for multiple PKGs. During forensic investigations, the legal authorities will be able to use the multiple PKG mechanism for data access, while an account locking mechanism prevents a single authority to access user data due to trust distribution. We also demonstrate that, the IBC scheme used in SCSS has better performance compared to similar schemes in the literature. For the security levels of 128-bits and above, SCSS has better scalability compared to existing schemes, with respect to encryption and decryption operations. Since the decryption operation is frequently needed for forensic analysis, the improved scalability results in a streamlined forensic investigation process on the encrypted data in the cloud.
机译:数据安全是云服务的最终用户是一个挑战,因为一旦它被传输到云中的用户对其数据的控制。一个潜在的损坏的云服务提供商能够获得最终用户的数据。传统的基于PKI的解决方案是不够的大型云系统,考虑到效率,可扩展性和安全性。在大规模的云系统,密钥管理要求,包括可扩展的加密,认证和不可抵赖性服务,以及有能力分享文件与不同的用户和数据恢复时加密数据的用户密钥不可访问。在云系统进一步要求包括一种用于在加密后的数据数字法庭调查提供的装置的能力。一旦在云上的数据与用户的密钥加密就不可能通过法医调查组访问。在这方面,分发密钥管理的信托成多个机构是可取的。在文献中,也没有可用的安全的云存储系统,安全和高效的类型3配对,支持加密作为一种服务(必需氨基酸)和多个公共密钥发生器(的PKG)。本文提出了一种安全的云存储高效的基于身份的密码(IBC)架构,名为安全云存储系统(SCSS),它支持分布式密钥管理和加密机制,支持多种的PKG。在取证调查,司法当局将能够使用的数据访问多个PKG机制,而一个帐户锁定机制可以防止单个授权用户的访问因信赖分布数据。我们还表明,相比于文献类似的计划在SCSS使用的IBC方案具有更好的性能。对于128位和上述安全等级,具有SCSS更好的可伸缩性比现有方案中,相对于加密和解密操作。由于解密操作,经常需要进行取证分析,在改进的可扩展性结果简化在云中的加密数据取证调查过程中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号