Abstract Attribute-based cloud storage with secure provenance over encrypted data
首页> 外文期刊>Future generation computer systems >Attribute-based cloud storage with secure provenance over encrypted data
【24h】

Attribute-based cloud storage with secure provenance over encrypted data

机译:基于属性的云存储,对加密数据具有安全的出处

获取原文
获取原文并翻译 | 示例
       

摘要

AbstractTo securely and conveniently enjoy the benefits of cloud storage, it is desirable to design a cloud data storage system which protects data privacy from storage servers through encryption, allows fine-grained access control such that data providers can expressively specify who are eligible to access the encrypted data, enables dynamic user management such that the total number of data users is unbounded and user revocation can be carried out conveniently, supports data provider anonymity and traceability such that a data provider’s identity is not disclosed to data users in normal circumstances but can be traced by a trusted authority if necessary, and equally important, provides secure data provenance by presenting irrefutable evidence on who has created and modified the data in the cloud. However, most of the existing cloud storage systems with secure provenance either lack the expressiveness in access control or incur too much performance overhead or do not support dynamic user management. In this paper, we solve these problems by presenting an attribute-based cloud storage system with secure provenance. We first give a simple construction without achieving user revocation, and then extend it with an efficient revocation mechanism to prevent revoked data users from accessing the newly encrypted data. Thereafter, we implement the algorithms in the proposed two constructions to evaluate their performance. Our experimental results show that the proposed systems are acceptable to be applied in practice.HighlightsThis paper focused on solving the problems in existing cloud storage systems with secure provenance.The proposed storage system with secure provenance in this paper protects data privacy, allows fine-grained access control, enables dynamic user management, supports data provider anonymity and traceability, and provides secure data provenance.This paper defined the formal security model and analysed the security for the proposed storage system.This paper conducted experiments on the proposed storage system to evaluate its performance.
机译: 摘要 为了安全方便地享受云存储的好处,设计一个云数据存储系统,该系统通过加密保护数据免受存储服务器的隐私,允许进行细粒度的访问控制,以便数据提供者可以表达性地指定谁有资格访问加密的数据,实现动态用户管理,从而使数据用户总数不受限制,可以方便地执行用户吊销,支持数据提供者的匿名性和可追溯性,以便在正常情况下不向数据用户公开数据提供者的身份,但是在必要时可以由受信任的权威机构跟踪,并且同样重要的是,提供安全的数据通过提供关于谁在云中创建和修改了数据的无可辩驳的证据来证明来源。但是,大多数现有的具有安全出处的云存储系统要么缺乏访问控制的表现力,要么会产生过多的性能开销,或者不支持动态用户管理。在本文中,我们通过提供具有安全来源的基于属性的云存储系统来解决这些问题。我们首先给出一个简单的结构而不实现用户撤销,然后使用有效的撤销机制对其进行扩展,以防止被撤销的数据用户访问新加密的数据。此后,我们在提出的两种构造中实施算法以评估其性能。我们的实验结果表明,提出的系统可以在实践中应用。 突出显示 本文重点关注以安全来源解决现有云存储系统中的问题。 “ p2 ”>本文中提出的具有安全出处的存储系统可以保护数据隐私,允许细粒度的访问控制,实现动态用户管理,支持数据提供者匿名性和可追溯性,并提供安全的数据保护。 本文定义了正式的安全模型并分析了所提议存储系统的安全性。 本文对建议的存储系统进行了实验,以评估其存储系统性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号