【24h】

Achieving Privacy-Preserving CP-ABE Access Control with Multi-Cloud

机译:通过多云实现保护隐私的CP-ABE访问控制

获取原文
获取原文并翻译 | 示例

摘要

Cloud storage service makes it very convenient for people to access and share data. At the same time, the confidentiality and privacy of user data is also facing great challenges. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) scheme is widely considered to be the most suitable security access control technology for cloud storage environment. Aiming at the problem of privacy leakage caused by single-cloud CP-ABE which is commonly adopted in the current schemes, this paper proposes a privacy-preserving CP-ABE access control scheme using multi-cloud architecture. By improving the traditional CP-ABE algorithm and introducing a proxy to cut the user's private key, it can ensure that only a part of the user attribute set can be obtained by a single cloud, which effectively protects the privacy of user attributes. Meanwhile, the intermediate logical structure of the access policy tree is stored in proxy, and only the leaf node information is stored in the ciphertext, which effectively protects the privacy of the access policy. Security analysis shows that our scheme is effective against replay and man-in-the-middle attacks, as well as user collusion attack. Experimental results also demonstrates that the multi-cloud CP-ABE does not significantly increase the overhead of storage and encryption compared to the single cloud scheme, but the access control overhead decreases as the number of clouds increases. When the access policy is expressed with a AND gate structure, the decryption overhead is obviously less than that of a single cloud environment.
机译:云存储服务使人们访问和共享数据变得非常方便。同时,用户数据的机密性和隐私性也面临着巨大的挑战。基于密文策略的基于属性的加密(CP-ABE)方案被广泛认为是最适合云存储环境的安全访问控制技术。针对当前方案中普遍采用的单云CP-ABE引起的隐私泄露问题,提出了一种采用多云体系结构的保护隐私的CP-ABE访问控制方案。通过改进传统的CP-ABE算法并引入代理来削减用户的私钥,可以确保单个云只能获取一部分用户属性集,从而有效地保护了用户属性的私密性。同时,访问策略树的中间逻辑结构存储在代理中,仅叶节点信息存储在密文中,有效地保护了访问策略的私密性。安全分析表明,我们的方案可以有效地防止重放和中间人攻击以及用户合谋攻击。实验结果还表明,与单云方案相比,多云CP-ABE不会显着增加存储和加密的开销,但是访问控制开销会随着云数量的增加而减少。当使用“与”门结构表示访问策略时,解密开销明显小于单个云环境的解密开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号