首页> 外文期刊>Automatic Control and Computer Sciences >Key Derivation Policy for Data Security and Data Integrity in Cloud Computing
【24h】

Key Derivation Policy for Data Security and Data Integrity in Cloud Computing

机译:云计算中数据安全性和数据完整性的密钥派生策略

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud computing is currently emerging as a promising next-generation architecture in the Information Technology (IT) industry and education sector. The encoding process of state information from the data and protection are governed by the organizational access control policies. An encryption technique protects the data confidentiality from the unauthorized access leads to the development of fine-grained access control policies with user attributes. The Attribute-Based Encryption (ABE) verifies the intersection of attributes to the multiple sets. The handling of adding or revoking the users is difficult with respect to changes in policies. The inclusion of multiple encrypted copies for the same key raised the computational cost. This paper proposes an efficient Key Derivation Policy (KDP) for improvement of data security and integrity in the cloud and overcomes the problems in traditional methods. The local key generation process in proposed method includes the data attributes. The secret key is generated from the combination of local keys with the user attribute by a hash function. The original text is recovered from the cipher text by the decryption process. The key sharing between data owner and user validates the data integrity referred MAC verification process. The proposed efficient KDP with MAC verification analyze the security issues and compared with the Cipher Text - Attribute-Based Encryption (CP-ABE) schemes on the performance parameters of encryption time, computational overhead and the average lifetime of key generation. The major advantage of proposed approach is the updating of public information and easy handling of adding/revoking of users in the cloud.
机译:当前,云计算正在成为信息技术(IT)行业和教育领域中有希望的下一代体系结构。来自数据和保护的状态信息的编码过程由组织访问控制策略控制。加密技术可保护数据机密性免受未经授权的访问,从而导致开发具有用户属性的细粒度访问控制策略。基于属性的加密(ABE)验证属性与多个集合的交集。关于策略的改变,增加或撤销用户的处理是困难的。为同一密钥包含多个加密副本会增加计算成本。本文提出了一种有效的密钥派生策略(KDP),以改善云中的数据安全性和完整性,并克服了传统方法中的问题。所提出的方法中的本地密钥生成过程包括数据属性。秘密密钥是通过哈希函数从本地密钥与用户属性的组合中生成的。通过解密过程从密文中恢复出原始文本。数据所有者和用户之间的密钥共享验证了MAC验证过程所涉及的数据完整性。提出的具有MAC验证的高效KDP分析了安全性问题,并在加密时间,计算开销和密钥生成的平均寿命等性能参数上与基于密文的基于密码的加密(CP-ABE)方案进行了比较。所提出的方法的主要优点是公共信息的更新以及云中用户添加/撤销的轻松处理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号