首页> 外文期刊>Cloud Computing, IEEE Transactions on >Efficient Decentralized Attribute Based Access Control for Mobile Clouds
【24h】

Efficient Decentralized Attribute Based Access Control for Mobile Clouds

机译:高效的移动云基于基于基于属性的访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

Fine grained access control is a requirement for data stored in untrusted servers like clouds. Owing to the large volume of data, decentralized key management schemes are preferred over centralized ones. Often encryption and decryption are quite expensive and not practical when users access data from resource constrained devices. We propose a decentralized attribute based encryption (ABE) scheme with fast encryption, outsourced decryption and user revocation. Our scheme is very specific to the context of mobile cloud as the storage of encrypted data and the partial decryption of ciphertexts are dependent on the cloud and users with mobile devices can upload data to the cloud or access data from it by incurring very little cost for encryption and decryption respectively. The main idea is to divide the encryption into two phases, offline preprocessing phase which is done when the device is otherwise not in use and an online phase when the data is actually encrypted with the policy. This makes encryption faster and more efficient than existing decentralized ABE schemes. For decryption outsourcing, data users need to generate a transformed version of the decryption key allowing an untrusted proxy server to partially decrypt the ciphertext without gaining any information about the plaintext. Data users can then fully decrypt the partially decrypted ciphertext without performing any costly pairing operations. We also introduce user revocation in this scheme without incurring too much additional cost in the online phase. Comparison with other ABE schemes shows that our scheme significantly reduces computation times for both data owners and data users and highly suitable for use in mobile devices.
机译:细粒度访问控制是存储在不受信任的服务器中的数据的要求。由于数据量大,分散的密钥管理方案在集中式中优先。当用户从资源受限设备访问数据时,经常加密和解密非常昂贵且不实用。我们提出了一种具有快速加密,外包解密和用户撤销的基于基于基于的基于属性的加密(ABE)的程序。我们的方案非常具体于移动云的上下文,因为加密数据的存储和密文的部分解密取决于云和移动设备的用户可以通过产生的成本将数据上传到云或从中访问数据。分别加密和解密。主要思想是将加密分为两个阶段,脱机预处理阶段,当数据实际加密时,当数据实际加密时,当设备无法使用时完成。这使得加密比现有的分散的ABE方案更快,更有效。对于解密外包,数据用户需要生成允许不受信任的代理服务器的解密密钥的转换版本,以便在不获得关于明文的任何信息的情况下部分解密密文。然后,数据用户可以完全解密部分解密的密文而不执行任何昂贵的配对操作。我们还在此方案中介绍了用户撤销,而不会在在线阶段产生太多的额外费用。与其他ABE方案的比较表明,我们的方案显着降低了数据所有者和数据用户的计算时间,并高度适用于移动设备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号