首页> 外文会议>2015 International Conference on Cloud Technologies and Applications >Decentralized attribute-based encryption scheme with scalable revocation for sharing data in public cloud servers
【24h】

Decentralized attribute-based encryption scheme with scalable revocation for sharing data in public cloud servers

机译:具有可扩展撤销功能的分散式基于属性的加密方案,用于在公共云服务器中共享数据

获取原文
获取原文并翻译 | 示例

摘要

With the rapid development of cloud computing, it is attractive for enterprise companies to outsource their data files for sharing in cloud servers, as cloud computing can offer desirable characteristics, such as on-demand self-service, broad network access, and rapid elasticity. However, by uploading data files onto cloud servers, data owners (i.e. the companies) will lose control over their own data. This makes it essential to use Attribute-based encryption (ABE) because it can help to protect the data confidentiality by uploading data files in encrypted form. In addition, it can help to facilitate granting access to data by allowing only authorized users to decrypt the encrypted data files based on a set of attributes. However, this ABE approach includes three key issues. The first one is the complexity of user secret key management for large-scale cloud environments. The second is the complexity of revoking the users access rights. The third is the computational complexity involved in assigning user rights, encrypting and accessing data files. This paper addresses these three issues by proposing a decentralized ciphertext-policy ABE scheme (CP-DABE) for a large-scale cooperative cloud environment. The scheme reduces the complexity of user secret key management by providing a secure attribute delegation services between a master authority and a number of multiple attribute authorities. The scheme also reduces the complexity of revocation process by using Proxy Re-encryption technique to revoke any users access right. In addition, by comparing with most relative work, the scheme reduces the computational requirements for assigning user rights, encrypting and accessing data files. The scheme can support any LSSS access structure. In this paper, the cryptographic construction of the CP-DABE scheme is presented, and its efficiency is analyzed and compared with most relative work. The security of the CP-DABE scheme is discussed and selectively proved against chosen-p- aintext attacks under the decisional Bilinear Diffie-Hellman Exponent assumption. Finally, ideas to extend the CP-DABE scheme are discussed.
机译:随着云计算的快速发展,企业公司将其数据文件外包以供在云服务器中共享的吸引力很大,因为云计算可以提供理想的特性,例如按需自助服务,广泛的网络访问和快速的弹性。但是,通过将数据文件上传到云服务器,数据所有者(即公司)将失去对自己数据的控制权。这使得必须使用基于属性的加密(ABE),因为它可以通过以加密形式上传数据文件来帮助保护数据机密性。另外,通过仅允许授权用户基于一组属性解密加密的数据文件,它可以帮助促进授予对数据的访问。但是,这种ABE方法包括三个关键问题。第一个是大规模云环境中用户密钥管理的复杂性。第二个是撤销用户访问权限的复杂性。第三是分配用户权限,加密和访问数据文件所涉及的计算复杂性。本文针对大型合作云环境提出了一种分散式密文策略ABE方案(CP-DABE),以解决这三个问题。该方案通过在主权限和多个多属性权限之间提供安全的属性委派服务,降低了用户密钥管理的复杂性。该方案还通过使用代理重新加密技术来撤消任何用户的访问权限,从而降低了撤消过程的复杂性。此外,通过与大多数相关工作进行比较,该方案降低了分配用户权限,加密和访问数据文件的计算要求。该方案可以支持任何LSSS访问结构。本文介绍了CP-DABE方案的密码结构,并对其效率进行了分析,并与大多数相关工作进行了比较。在决策双线性Diffie-Hellman指数假设下,讨论了CP-DABE方案的安全性并针对选择的p-intext攻击进行了有选择的证明。最后,讨论了扩展CP-DABE方案的想法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号