...
首页> 外文期刊>Information Security, IET >P2 KASE A2—privacy-preserving key aggregate searchable encryption supporting authentication and access control on multi-delegation
【24h】

P2 KASE A2—privacy-preserving key aggregate searchable encryption supporting authentication and access control on multi-delegation

机译:P2 Kase A2-Privacy保留密钥聚合可搜索的加密支持多委托的身份验证和访问控制

获取原文
获取原文并翻译 | 示例

摘要

Delegation is a technique that allows a subject receiving a delegation (the delegatee) to act on behalf of the delegating subject (the delegator). Although the existing Key Aggregate Searchable Encryption (KASE) schemes support delegation of search rights over any set of ciphertexts using a key of constant-size, two critical issues still should be considered. Firstly, an adversary can intercept the aggregate key or query trapdoor from the insecure communication channels involving the cloud server and impersonate as an authorized user to the server for accessing the data. Secondly, the existing KASE schemes only discuss the delegation of rights from the data owner to other users. However, if a subject receiving a delegation cannot perform the time-critical task on the shared data because of the unavailability, it becomes necessary for the delegatee to further delegate his received rights to another user. In this paper, we propose a novel KASE scheme that allows a fine-grained multi-delegation, i.e., if the attributes of the delegatee satisfy the hidden access policy (defined by the data owner), the delegatee can delegate his received rights to another user, without compromising data privacy. The proposed scheme provides security against the impersonation attack by verifying the user's authentication.
机译:代表团是一种技术,允许接受代表团(代表人)的主题代表授权主题(代理人)行事。虽然现有的密钥聚合搜索加密(Kase)在使用常量大小的键的任何一组密码上支持搜索权限的委托,但仍应考虑两个关键问题。首先,对手可以从涉及云服务器的不安全的通信信道拦截聚合键或查询陷阱,并将作为授权用户冒充用于访问数据的服务器。其次,现有的kase方案仅讨论从数据所有者到其他用户的权利委派。但是,如果由于不可用,接收委托的主题无法对共享数据执行时间关键任务,则该代表人必须进一步将其接收权委托给另一个用户所必需的。在本文中,我们提出了一种新颖的Kase方案,允许一个细粒度的多委托,即,如果代表人的属性满足隐藏的访问策略(由数据所有者定义),则该代表可以将其接收权委派给另一个用户,不影响数据隐私。该方案通过验证用户的身份验证,提供了对模拟攻击的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号