首页> 外文会议>IEEE International Conference on Cloud Computing Technology and Science >A secure and efficient revocation scheme for fine-grained access control in cloud storage
【24h】

A secure and efficient revocation scheme for fine-grained access control in cloud storage

机译:云存储中细粒度访问控制的安全有效的吊销方案

获取原文

摘要

To keep data confidential against unauthorized cloud servers and users, cryptographic access control mechanisms must be adopted. However, user revocation is a challenging issue since it would inevitably require data re-encryption, and may need user secret key updates. Considering the complexity of fine-grained access control policy and the large number of users in cloud, this issue would become extremely difficult to resolve. In this paper, we focus on this challenging open issue and present a secure and efficient revocation scheme. We propose a modified CP-ABE algorithm to set up a fine-grained access control method, in which user revocation is achieved based on the theory of Shamir's Secret Sharing. Compared with existing schemes, our scheme introduces a minimal overhead not only to the data owner but also to cloud servers. Collusions between cloud servers and revoked users can be avoided as long as the key-update protocol is honestly executed. Meanwhile, the data owner can delegate key updates to the cloud servers without disclosing data contents, user attributes, and the access policy information. Moreover, our scheme maintains the important feature that the revocation won't affect the users whose attribute set is a superset of the revoked user's.
机译:为了使数据保密,不授权云服务器和用户,必须采用加密访问控制机制。但是,用户撤销是一个具有挑战性的问题,因为它不可避免地需要数据重新加密,并且可能需要用户密钥更新。考虑到细粒度访问控制政策的复杂性和云中大量用户,这个问题将变得非常难以解决。在本文中,我们专注于这一具有挑战性的开放问题,并提出了一种安全有效的撤销计划。我们提出了一种修改的CP-ABE算法来建立一个细粒度的访问控制方法,其中基于Shamir秘密共享理论实现了用户撤销。与现有方案相比,我们的方案不仅引入了最小的开销,不仅是数据所有者,还引入了云服务器。只要诚实执行键更新协议,就可以避免云服务器和撤销用户之间的勾劳。同时,数据所有者可以将密钥更新委派给云服务器,而无需披露数据内容,用户属性和访问策略信息。此外,我们的方案维护了撤销不会影响其属性集是撤销用户的超集的重要功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号