...
首页> 外文期刊>Sensors >A Hybrid Scheme for Fine-Grained Search and Access Authorization in Fog Computing Environment
【24h】

A Hybrid Scheme for Fine-Grained Search and Access Authorization in Fog Computing Environment

机译:雾计算环境中细粒度搜索和访问授权的混合方案

获取原文

摘要

In the fog computing environment, the encrypted sensitive data may be transferred to multiple fog nodes on the edge of a network for low latency; thus, fog nodes need to implement a search over encrypted data as a cloud server. Since the fog nodes tend to provide service for IoT applications often running on resource-constrained end devices, it is necessary to design lightweight solutions. At present, there is little research on this issue. In this paper, we propose a fine-grained owner-forced data search and access authorization scheme spanning user-fog-cloud for resource constrained end users. Compared to existing schemes only supporting either index encryption with search ability or data encryption with fine-grained access control ability, the proposed hybrid scheme supports both abilities simultaneously, and index ciphertext and data ciphertext are constructed based on a single ciphertext-policy attribute based encryption (CP-ABE) primitive and share the same key pair, thus the data access efficiency is significantly improved and the cost of key management is greatly reduced. Moreover, in the proposed scheme, the resource constrained end devices are allowed to rapidly assemble ciphertexts online and securely outsource most of decryption task to fog nodes, and mediated encryption mechanism is also adopted to achieve instantaneous user revocation instead of re-encrypting ciphertexts with many copies in many fog nodes. The security and the performance analysis show that our scheme is suitable for a fog computing environment.
机译:在雾计算环境中,可以将加密的敏感数据传输到网络边缘的多个雾节点,以降低延迟。因此,雾节点需要实现对加密数据的搜索,作为云服务器。由于雾节点倾向于为经常在资源受限的终端设备上运行的物联网应用提供服务,因此有必要设计轻型解决方案。目前,对此问题的研究很少。在本文中,我们针对资源受限的最终用户提出了一种跨用户雾云的细粒度的所有者强制数据搜索和访问授权方案。与仅支持具有搜索能力的索引加密或具有细粒度访问控制能力的数据加密的现有方案相比,所提出的混合方案同时支持这两种能力,并且基于基于单个密文策略策略属性的加密构造了索引密文和数据密文。 (CP-ABE)原语并共享相同的密钥对,从而显着提高了数据访问效率,并大大降低了密钥管理的成本。此外,在所提出的方案中,允许资源受限的终端设备快速地在线组装密文,并将大部分解密任务安全地外包给雾节点,并且还采用了介导的加密机制来实现瞬时用户吊销,而不是用许多方法重新加密密文。在许多雾节点中复制。安全性和性能分析表明,该方案适用于雾计算环境。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号