首页> 外文期刊>Cloud Computing, IEEE Transactions on >DaSCE: Data Security for Cloud Environment with Semi-Trusted Third Party
【24h】

DaSCE: Data Security for Cloud Environment with Semi-Trusted Third Party

机译:DaSCE:具有半信任第三方的云环境数据安全

获取原文
获取原文并翻译 | 示例

摘要

Off-site data storage is an application of cloud that relieves the customers from focusing on data storage system. However, outsourcing data to a third-party administrative control entails serious security concerns. Data leakage may occur due to attacks by other users and machines in the cloud. Wholesale of data by cloud service provider is yet another problem that is faced in the cloud environment. Consequently, high-level of security measures is required. In this paper, we propose data security for cloud environment with semi-trusted third party (DaSCE), a data security system that provides (a) key management (b) access control, and (c) file assured deletion. The DaSCE utilizes Shamir's (k, n) threshold scheme to manage the keys, where k out of n shares are required to generate the key. We use multiple key managers, each hosting one share of key. Multiple key managers avoid single point of failure for the cryptographic keys. We (a) implement a working prototype of DaSCE and evaluate its performance based on the time consumed during various operations, (b) formally model and analyze the working of DaSCE using high level petri nets (HLPN), and (c) verify the working of DaSCE using satisfiability modulo theories library (SMT-Lib) and Z3 solver. The results reveal that DaSCE can be effectively used for security of outsourced data by employing key management, access control, and file assured deletion.
机译:异地数据存储是一种云应用程序,可减轻客户对数据存储系统的关注。但是,将数据外包给第三方管理控制会带来严重的安全隐患。可能由于云中其他用户和计算机的攻击而发生数据泄漏。云服务提供商的数据批发是云环境中面临的另一个问题。因此,需要高级别的安全措施。在本文中,我们提出了具有半托管第三方(DaSCE)的云环境数据安全性,该数据安全系统提供(a)密钥管理(b)访问控制和(c)文件保证删除。 DaSCE利用Shamir(k,n)阈值方案来管理密钥,其中需要n个共享中的k个来生成密钥。我们使用多个密钥管理器,每个密钥管理器托管一个密钥。多个密钥管理器可避免加密密钥的单点故障。我们(a)实施DaSCE的工作原型,并根据各种操作消耗的时间评估其性能,(b)使用高级Petri网(HLPN)正式建模和分析DaSCE的工作,并且(c)验证工作使用可满足性模理论库(SMT-Lib)和Z3求解器对DaSCE进行分析。结果表明,通过采用密钥管理,访问控制和文件保证删除,DaSCE可以有效地用于外包数据的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号