首页> 外文期刊>Computers & Security >How to implement secure cloud file sharing using optimized attribute-based access control with small policy matrix and minimized cumulative errors
【24h】

How to implement secure cloud file sharing using optimized attribute-based access control with small policy matrix and minimized cumulative errors

机译:如何使用具有小策略矩阵的优化属性的访问控制来实现安全云文件共享,并最小化累积错误

获取原文
获取原文并翻译 | 示例

摘要

The stunning growth of Internet users through Cloud File Sharing (CFS) is raising great concerns about unprecedented cloud security and privacy breach. Also, the recent breakthrough in quantum computing further reinforces this kind of concerns, thus we exploit an efficient solution to guarantee personal privacy and resist quantum attacks in the CFS service. In our solution, we integrate the Attribute-based Access Control/eXtensible Access Control Markup Language (ABAC/XACML) model and the Ciphertext-Policy Attribute-Based Encryption (CP-ABE) into the CFS. To improve the performance of CP-ABE, we make use of an optimization method to convert the ABAC/XACML policy into a Small Policy Matrix (SPM). We further prove that this matrix has small coefficients and generates an all-one reconstruction vector, such that it reduces the cumulative error in lattice cryptosystem to the minimum. By using the SPM, we design a new CP-ABE scheme from Lattice (CP-ABE-L) to prevent the enlargement of error bounds. We also give the optimal estimation of system parameters, which satisfy three lattice-generation conditions to implement a valid Error Proportion Allocation (EPA). Our scheme is proved secure against chosen-plaintext attack with a selective attribute set under the Decision Learning with Errors (DLWE) assumption in the standard model. The performance evaluation and analyses illustrate that our scheme not only has short parameters, but also maintains efficient computation and reasonable storage overloads.
机译:通过云文件共享(CFS)令人惊叹的互联网用户的增长是对前所未有的云安全和隐私违规的令人震惊。此外,近期Quantum Computing的突破进一步加强了这种关注,因此我们利用有效的解决方案来保证个人隐私和抵抗CFS服务中的量子攻击。在我们的解决方案中,我们将基于属性的访问控制/可扩展访问控制标记语言(ABAC / XACML)和基于CFS的加密(CP-ABE)集成到CFS中。为了提高CP-ABE的性能,我们利用优化方法将ABAC / XACML策略转换为小型策略矩阵(SPM)。我们进一步证明,该矩阵具有小的系数并产生全面的重建矢量,使得它将晶格密码系统中的累积误差降低到最小值。通过使用SPM,我们设计一种从格子(CP-ABE-L)的新CP-APE方案,以防止误差界限。我们还提供了对系统参数的最佳估计,其满足三个格子生成条件来实现有效的误差比例分配(EPA)。通过在标准模型中的错误(DLWE)假设的决策学习下,我们的计划被证明是防止选择性的属性集中的选择性属性。性能评估和分析说明我们的方案不仅具有短的参数,而且还保持有效的计算和合理的存储过载。

著录项

  • 来源
    《Computers & Security》 |2021年第8期|102318.1-102318.20|共20页
  • 作者单位

    School of Computer and Communication Engineering University of Science and Technology Beijing 10083 China;

    School of Computer and Communication Engineering University of Science and Technology Beijing 10083 China;

    Data Communication Science and Technology Research Institute 100191 China;

    Delft University of Technology Van Mourik Broekmanweg 6 2628 XE Delft Netherlands;

    School of Mathematical Sciences Peking University 100871 China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Security; Privacy; Cloud file sharing; Post-Quantum security; Attribute-Based encryption; Small policy matrix;

    机译:安全;隐私;云文件共享;后量子安全;基于属性的加密;小政策矩阵;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号