首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >A Secure Erasure Code-Based Cloud Storage System with Secure Data Forwarding
【24h】

A Secure Erasure Code-Based Cloud Storage System with Secure Data Forwarding

机译:具有安全数据转发功能的基于安全擦除代码的云存储系统

获取原文
获取原文并翻译 | 示例
           

摘要

A cloud storage system, consisting of a collection of storage servers, provides long-term storage services over the Internet. Storing data in a third party's cloud system causes serious concern over data confidentiality. General encryption schemes protect data confidentiality, but also limit the functionality of the storage system because a few operations are supported over encrypted data. Constructing a secure storage system that supports multiple functions is challenging when the storage system is distributed and has no central authority. We propose a threshold proxy re-encryption scheme and integrate it with a decentralized erasure code such that a secure distributed storage system is formulated. The distributed storage system not only supports secure and robust data storage and retrieval, but also lets a user forward his data in the storage servers to another user without retrieving the data back. The main technical contribution is that the proxy re-encryption scheme supports encoding operations over encrypted messages as well as forwarding operations over encoded and encrypted messages. Our method fully integrates encrypting, encoding, and forwarding. We analyze and suggest suitable parameters for the number of copies of a message dispatched to storage servers and the number of storage servers queried by a key server. These parameters allow more flexible adjustment between the number of storage servers and robustness.
机译:由存储服务器集合组成的云存储系统通过Internet提供长期存储服务。将数据存储在第三方的云系统中会引起对数据机密性的严重关注。通用加密方案可保护数据机密性,但同时也限制了存储系统的功能,因为对加密数据支持一些操作。当存储系统是分布式的并且没有中央权限时,构建支持多种功能的安全存储系统是一项挑战。我们提出了一种阈值代理重新加密方案,并将其与分散的擦除代码集成在一起,从而制定了安全的分布式存储系统。分布式存储系统不仅支持安全可靠的数据存储和检索,而且还允许用户将其在存储服务器中的数据转发给另一个用户而无需取回数据。主要的技术贡献在于,代理重新加密方案支持对加密消息进行编码操作以及对编码和加密消息进行转发操作。我们的方法完全集成了加密,编码和转发。我们分析并建议合适的参数,用于分配给存储服务器的消息的副本数和密钥服务器查询的存储服务器数。这些参数允许在存储服务器的数量和健壮性之间进行更灵活的调整。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号