首页> 外文期刊>IEEE transactions on information forensics and security >EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the Cloud
【24h】

EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the Cloud

机译:EACSIP:具有完整性保护功能的可扩展访问控制系统,用于增强云中的协作

获取原文
获取原文并翻译 | 示例
       

摘要

It is widely acknowledged that the collaborations with more users increase productivity. Secure cloud storage is a promising tool to enhance such a collaboration. Access control system can be enabled with attribute-based encryption. In this system, a user encrypts and uploads his/her data to the cloud with an access policy, such that only people who satisfy that access policy can decrypt the data. When a recipient would like to enable another person who is originally unauthorized by the original access policy, this recipient will need to extend the access policy by adding a new policy that includes the new person hence, the notion of extendable access control system. Admitting new users to access the uploaded data is an important requirement in enhancing collaborations. The main issue is with regards to the integrity protection during the process of extending the access policy. When a new access policy is added, the cloud has to be sure that the extended access policy remains guarding the same encrypted data as the original access policy, even though the cloud cannot decrypt this ciphertext, which is a challenging problem to solve. In this paper, we answer the above problem affirmatively by introducing an extendable access control system with Integrity Protection (EACSIP), which is suitable to enhance collaboration in the cloud. The construction of EACSIP is built on top of a novel cryptographic primitive, namely functional key encapsulation with equality testing. The security proof and the performance evaluation of EACSIP are provided in this paper.
机译:众所周知,与更多用户的协作可以提高生产率。安全的云存储是增强这种协作的有前途的工具。可以使用基于属性的加密来启用访问控制系统。在该系统中,用户使用访问策略对自己的数据进行加密并将其上传到云中,这样只有满足访问策略的人才能解密数据。当接收者想要启用最初受到原始访问策略未授权的其他人时,该接收者将需要通过添加包括新用户在内的新策略来扩展访问策略,从而扩展可扩展访问控制系统的概念。允许新用户访问上载的数据是增强协作的重要要求。主要问题与扩展访问策略过程中的完整性保护有关。当添加新的访问策略时,即使云无法解密该密文,云也必须确保扩展访问策略仍保持与原始访问策略相同的加密数据,这是一个具有挑战性的问题。在本文中,我们通过引入具有完整性保护(EACSIP)的可扩展访问控制系统来肯定地回答上述问题,该系统适用于增强云中的协作。 EACSIP的构建建立在一种新颖的加密原语之上,即具有相等性测试的功能性密钥封装。本文提供了EACSIP的安全性证明和性能评估。

著录项

  • 来源
  • 作者单位

    School of Computing and Information Technology, Institute of Cybersecurity and Cryptology, University of Wollongong, Wollongong, NSW, Australia;

    Department of Computing, The Hong Kong Polytechnic University, Hong Kong;

    School of Computing and Information Technology, Institute of Cybersecurity and Cryptology, University of Wollongong, Wollongong, NSW, Australia;

    School of Computing and Information Technology, Institute of Cybersecurity and Cryptology, University of Wollongong, Wollongong, NSW, Australia;

    School of Computer Science, Shaanxi Normal University, Xi’an, China;

    School of Computing and Information Technology, Institute of Cybersecurity and Cryptology, University of Wollongong, Wollongong, NSW, Australia;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cloud computing; Access control; Encryption; Collaboration; Servers; Companies;

    机译:云计算;访问控制;加密;协作;服务器;公司;
  • 入库时间 2022-08-17 13:05:58

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号