首页> 外文会议>IEEE International conference on cloud computing >Privacy-Preserving Decentralized Access Control for Cloud Storage Systems
【24h】

Privacy-Preserving Decentralized Access Control for Cloud Storage Systems

机译:云存储系统的隐私保护分散式访问控制

获取原文

摘要

Along with a large amount of data being outsourced to the cloud, it is imperative to enforce a secure, efficient and privacy-aware access control scheme on the cloud. Decentralized Attribute-based Encryption (ABE) is a variant of multi-authority ABE scheme which is regarded as being more suited to access control in a large-scale cloud. Constructing a decentralized ABE scheme should not need a central Attribute Authority (AA) and any cooperative computing, where most schemes are not efficient enough. Moreover, they introduced a Global Identifier (GID) to resist the collusion attack from users, but corrupt AAs can trace a user by his GID, resulting in the leakage of the user's identity privacy. In this paper, we design a privacy-preserving decentralized access control framework for cloud storage systems, and propose a decentralized CP-ABE access control scheme with the privacy preserving secret key extraction. Our scheme does not require any central AA and coordination among multi-authorities. We adopt Pedersen commitment scheme and oblivious commitment based envelope protocols as the main cryptographic primitives to address the privacy problem, thus the users receive secret keys only for valid identity attributes while the AAs learn nothing about the attributes. Our theoretical analysis and extensive experiment demonstrate the presented scheme's security strength and effectiveness in terms of scalability, computation and storage.
机译:随着大量数据外包给云,必须在云上实施安全,高效和隐私感知的访问控制方案。基于分散属性的加密(ABE)是多权限ABE方案的一种变体,被认为更适合大规模云中的访问控制。构建分散的ABE方案应该不需要中央属性授权机构(AA)和任何协作计算,而大多数方案效率都不高。此外,他们引入了全局标识符(GID)来抵抗来自用户的串通攻击,但是损坏的AA可以通过其GID来跟踪用户,从而导致用户身份隐私的泄漏。本文设计了一种用于云存储系统的隐私保护的分散访问控制框架,并提出了一种具有隐私保护秘密密钥提取的分散式CP-ABE访问控制方案。我们的计划不需要任何中央AA和多机构之间的协调。我们采用Pedersen承诺方案和基于遗忘承诺的信封协议作为主要的加密原语来解决隐私问题,因此,用户仅收到有效身份属性的密钥,而AA对该属性一无所知。我们的理论分析和广泛的实验证明了该方案在可伸缩性,计算和存储方面的安全强度和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号