首页> 外文会议>2012 IEEE 4th International Conference on Cloud Computing Technology and Science. >A secure and efficient revocation scheme for fine-grained access control in cloud storage
【24h】

A secure and efficient revocation scheme for fine-grained access control in cloud storage

机译:一种安全高效的撤销方案,用于云存储中的细粒度访问控制

获取原文
获取原文并翻译 | 示例

摘要

To keep data confidential against unauthorized cloud servers and users, cryptographic access control mechanisms must be adopted. However, user revocation is a challenging issue since it would inevitably require data re-encryption, and may need user secret key updates. Considering the complexity of fine-grained access control policy and the large number of users in cloud, this issue would become extremely difficult to resolve. In this paper, we focus on this challenging open issue and present a secure and efficient revocation scheme. We propose a modified CP-ABE algorithm to set up a fine-grained access control method, in which user revocation is achieved based on the theory of Shamir's Secret Sharing. Compared with existing schemes, our scheme introduces a minimal overhead not only to the data owner but also to cloud servers. Collusions between cloud servers and revoked users can be avoided as long as the key-update protocol is honestly executed. Meanwhile, the data owner can delegate key updates to the cloud servers without disclosing data contents, user attributes, and the access policy information. Moreover, our scheme maintains the important feature that the revocation won't affect the users whose attribute set is a superset of the revoked user's.
机译:为了使数据对未经授权的云服务器和用户保密,必须采用加密访问控制机制。但是,用户撤销是一个具有挑战性的问题,因为它不可避免地需要重新加密数据,并且可能需要更新用户密钥。考虑到细粒度的访问控制策略的复杂性以及云中的大量用户,此问题将变得非常难以解决。在本文中,我们将重点放在这个具有挑战性的公开问题上,并提出一种安全有效的撤销方案。我们提出了一种改进的CP-ABE算法,以建立一种细粒度的访问控制方法,该方法基于Shamir的秘密共享理论实现了用户撤销。与现有方案相比,我们的方案不仅为数据所有者而且为云服务器引入了最小的开销。只要诚实执行密钥更新协议,就可以避免云服务器与被撤消用户之间的共谋。同时,数据所有者可以将密钥更新委派给云服务器,而无需透露数据内容,用户属性和访问策略信息。而且,我们的方案保持了重要的特征,即撤销不会影响其属性集是被撤销用户的超集的用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号