首页> 外文会议>International Symposium on Security and Privacy in Social Networks and Big Data >A Secure and Efficient Data Sharing Framework with Delegated Capabilities in Hybrid Cloud
【24h】

A Secure and Efficient Data Sharing Framework with Delegated Capabilities in Hybrid Cloud

机译:具有混合云中的委派功能的安全有效的数据共享框架

获取原文

摘要

Hybrid cloud is a widely used cloud architecture in large companies that can outsource data to the public cloud, while still supporting various clients like mobile devices. However, such public cloud data outsourcing raises serious security concerns, such as how to preserve data confidentiality and how to regulate access policies to the data stored in public cloud. To address this issue, we design a hybrid cloud architecture that supports data sharing securely and efficiently, even with resource-limited devices, where private cloud serves as a gateway between the public cloud and the data user. Under such architecture, we propose an improved construction of attribute-based encryption that has the capability of delegating encryption/decryption computation, which achieves flexible access control in the cloud and privacy-preserving in data utilization even with mobile devices. Extensive experiments show the scheme can further decrease the computational cost and space overhead at the user side, which is quite efficient for the user with limited mobile devices. In the process of delegating most of the encryption/decryption computation to private cloud, the user can not disclose any information to the private cloud. We also consider the communication security that once frequent attribute revocation happens, our scheme is able to resist some attacks between private cloud and data user by employing anonymous key agreement.
机译:混合云是一个广泛使用的云体系结构,可以在大型公司中外包给公共云,同时仍然支持像移动设备这样的各种客户端。但是,这种公共云数据外包提出了严重的安全问题,例如如何保留数据机密性以及如何调节存储在公共云中的数据的访问策略。为了解决这个问题,我们设计了一种混合云体系结构,即使使用资源限制设备,私有云作为公共云和数据用户之间的网关,也可以安全地和有效地支持数据共享的混合云架构。在这种架构下,我们提出了改进的基于基于属性的加密构造,该加密具有委派加密/解密计算的能力,该加密/解密计算即使使用移动设备也可以在云中实现灵活的访问控制和数据利用中的隐私保留。广泛的实验表明,该方案可以进一步降低用户侧的计算成本和空间开销,这对于具有有限移动设备的用户来说非常有效。在将大多数加密/解密计算委派给私有云的过程中,用户无法向私有云披露任何信息。我们还考虑频繁属性撤销发生的通信安全性,我们的方案能够通过采用匿名密钥协议来抵制私有云和数据用户之间的一些攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号