首页> 外文期刊>Future generation computer systems >Decentralized attribute-based conjunctive keyword search scheme with online/offline encryption and outsource decryption for cloud computing
【24h】

Decentralized attribute-based conjunctive keyword search scheme with online/offline encryption and outsource decryption for cloud computing

机译:基于分散属性的在线/离线加密和外包解密的基于属性的联合关键字搜索方案,用于云计算

获取原文
获取原文并翻译 | 示例

摘要

In recent years, the increasing popularity of cloud computing has led to a trend that data owners prefer to outsource their data to the clouds for the enjoyment of the on-demand storage and computing services. For security and privacy concerns, fine-grained access control and secure data retrieval for the outsourced data is of critical importance. Attribute-based keyword search (ABKS) scheme, as a cryptographic primitive which explores the notion of public key encryption with keyword search (PEKS) into the context of attribute-based encryption (ABE), can enable the data owner to flexibly share his data to a specified group of users satisfying the access policy and meanwhile, maintain the confidentiality and searchable properties of the sensitive data. However, in most of the previous ABKS schemes, the decryption service is not provided, and a fully trusted central authority is required, which is not practical in the scenario that the access policy is written over attributes or credentials issued across different trust domains and organizations. Moreover, the efficiency of storage and computation is also the bottleneck of implementation of ABKS scheme. In this paper, for the first time, we propose a decentralized ABKS scheme with conjunctive keyword search for the cloud storage system. Besides the multi-keyword search in the decentralized setting, our scheme outsources the undesirable costly operations of decryption to the cloud without degrading the user's privacy. Furthermore, the encryption phase is also divided into two phases, an offline pre-computation phase which is independent with the plaintext message, access policy, and keyword set, and can be performed at any time when the data owner's device is otherwise not in use, and an online encryption phase which only incurs very little computation costs. Security analysis indicates that our scheme is provably secure in the random oracle model. The asymptotic complexity comparison and simulation results also show that our scheme achieves high computation efficiency. (C) 2019 Elsevier B.V. All rights reserved.
机译:近年来,云计算的日益普及导致数据所有者倾向于将其数据外包给云以享受按需存储和计算服务的趋势。对于安全和隐私问题,细粒度的访问控制和对外包数据的安全数据检索至关重要。基于属性的关键字搜索(ABKS)方案作为一种加密原语,将基于关键字搜索(PEKS)的公钥加密概念探索到基于属性的加密(ABE)的上下文中,可以使数据所有者灵活地共享其数据满足访问策略的指定用户组,同时保持敏感数据的机密性和可搜索属性。但是,在大多数以前的ABKS方案中,没有提供解密服务,并且需要完全受信任的中央机构,这在访问策略是基于在不同信任域和组织之间发布的属性或凭据上写入的情况下不可行。 。而且,存储和计算的效率也是ABKS方案实现的瓶颈。本文首次针对云存储系统提出了一种带有联合关键词搜索的分散式ABKS方案。除了在分散式环境中进行多关键字搜索外,我们的方案还将不希望的,昂贵的解密操作外包到云中,而不会降低用户的隐私。此外,加密阶段还分为两个阶段,即脱机预计算阶段,该阶段与明文消息,访问策略和关键字集无关,并且可以在不使用数据所有者设备的任何时间执行,并且在线加密阶段仅产生很少的计算成本。安全分析表明,我们的方案在随机预言模型中是可证明的安全性。渐近复杂度的比较和仿真结果也表明,该方案具有较高的计算效率。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号