首页> 外文期刊>International Journal of Innovative Computing and Applications >Formal analysis of a private access control protocol to a cloud storage
【24h】

Formal analysis of a private access control protocol to a cloud storage

机译:云存储私人访问控制协议的正式分析

获取原文
获取原文并翻译 | 示例
       

摘要

Cloud storage provides an attractive solution for many organisations and enterprises due to its features such as scalability, availability and reduced costs. However, storing data in the cloud is challenging if we want to ensure data security and user privacy. To address these security issues cryptographic protocols are usually used. Such protocols rely on cryptographic primitives which have to guarantee some security properties such that data and user privacy or authentication. Attribute-based signature (ABS) and attribute-based encryption (ABE) are very adapted for storing data on an untrusted remote entity. In this work, we enhance the security of cloud storage systems through a formal analysis of a cloud storage protocol based on ABS and ABE schemes. We clarify several ambiguities in the design of this protocol and model the protocol and its security properties with ProVerif an automatic tool for the verification of cryptographic protocols. We discover an unknown attack against user privacy in the Ruj et al. (2012) protocol. We propose a correction, and automatically prove the security of the corrected protocol with ProVerif.
机译:由于其功能,可扩展性,可用性和成本降低,云存储为许多组织和企业提供了有吸引力的解决方案。但是,如果我们希望确保数据安全性和用户隐私,将云中的数据存储在挑战。为了解决这些安全问题,通常使用密码协议。此类协议依赖于加密原语,这必须保证某些安全性质,使数据和用户隐私或身份验证。基于属性的签名(ABS)和基于属性的加密(ABE)非常适合于将数据存储在不可信任的远程实体上。在这项工作中,我们通过基于ABS和ABE方案的云存储协议的正式分析来增强云存储系统的安全性。我们在设计此协议的设计中阐明了多个模糊性,并使用箴言自动工具为授予纤维图来验证加密协议的自动工具。我们在Ruj等人中发现了针对用户隐私的未知攻击。 (2012)议定书。我们提出了一种纠正,并自动证明替代方案的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号