...
首页> 外文期刊>Systems Engineering and Electronics, Journal of >Multi-authority proxy re-encryption based on CPABE for cloud storage systems
【24h】

Multi-authority proxy re-encryption based on CPABE for cloud storage systems

机译:基于CPABE的云存储系统多权限代理重新加密

获取原文
获取原文并翻译 | 示例
           

摘要

The dissociation between data management and data ownership makes it difficult to protect data security and privacy in cloud storage systems. Traditional encryption technologies are not suitable for data protection in cloud storage systems. A novel multi-authority proxy re-encryption mechanism based on ciphertext-policy attribute-based encryption (MPRE-CPABE) is proposed for cloud storage systems. MPRE-CPABE requires data owner to split each file into two blocks, one big block and one small block. The small block is used to encrypt the big one as the private key, and then the encrypted big block will be uploaded to the cloud storage system. Even if the uploaded big block of file is stolen, illegal users cannot get the complete information of the file easily. Ciphertext-policy attribute-based encryption (CPABE) is always criticized for its heavy overload and insecure issues when distributing keys or revoking user's access right. MPRE-CPABE applies CPABE to the multi-authority cloud storage system, and solves the above issues. The weighted access structure (WAS) is proposed to support a variety of fine-grained threshold access control policy in multi-authority environments, and reduce the computational cost of key distribution. Meanwhile, MPRE-CPABE uses proxy re-encryption to reduce the computational cost of access revocation. Experiments are implemented on platforms of Ubuntu and CloudSim. Experimental results show that MPRE-CPABE can greatly reduce the computational cost of the generation of key components and the revocation of user's access right. MPRE-CPABE is also proved secure under the security model of decisional bilinear Diffie-Hellman (DBDH).
机译:数据管理与数据所有权之间的分离使得难以保护云存储系统中的数据安全性和隐私性。传统的加密技术不适用于云存储系统中的数据保护。针对云存储系统,提出了一种基于密文策略基于属性的加密(MPRE-CPABE)的新型多机构代理重加密机制。 MPRE-CPABE要求数据所有者将每个文件分成两个块,一个大块和一个小块。小块用于加密大块作为私钥,然后将加密的大块上载到云存储系统。即使上载的大文件块被盗,非法用户也无法轻松获取文件的完整信息。基于密码文本策略的基于属性的加密(CPABE)总是因分配密钥或撤消用户的访问权限时的重载和不安全问题而受到批评。 MPRE-CPABE将CPABE应用于多权限云存储系统,并解决了上述问题。提出了加权访问结构(WAS)以支持多权限环境中的各种细粒度阈值访问控制策略,并减少密钥分发的计算成本。同时,MPRE-CPABE使用代理重新加密来减少访问吊销的计算成本。实验是在Ubuntu和CloudSim平台上实施的。实验结果表明,MPRE-CPABE可以大大降低生成关键组件和撤销用户访问权限的计算成本。在决策双线性Diffie-Hellman(DBDH)的安全模型下,MPRE-CPABE也被证明是安全的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号