...
首页> 外文期刊>Future generation computer systems >Decentralized attribute-based conjunctive keyword search scheme with online/offline encryption and outsource decryption for cloud computing
【24h】

Decentralized attribute-based conjunctive keyword search scheme with online/offline encryption and outsource decryption for cloud computing

机译:基于分散的属性的联合关键字搜索方案,具有在线/离线加密和外包云计算解密

获取原文
获取原文并翻译 | 示例
           

摘要

In recent years, the increasing popularity of cloud computing has led to a trend that data owners prefer to outsource their data to the clouds for the enjoyment of the on-demand storage and computing services. For security and privacy concerns, fine-grained access control and secure data retrieval for the outsourced data is of critical importance. Attribute-based keyword search (ABKS) scheme, as a cryptographic primitive which explores the notion of public key encryption with keyword search (PEKS) into the context of attribute-based encryption (ABE), can enable the data owner to flexibly share his data to a specified group of users satisfying the access policy and meanwhile, maintain the confidentiality and searchable properties of the sensitive data. However, in most of the previous ABKS schemes, the decryption service is not provided, and a fully trusted central authority is required, which is not practical in the scenario that the access policy is written over attributes or credentials issued across different trust domains and organizations. Moreover, the efficiency of storage and computation is also the bottleneck of implementation of ABKS scheme. In this paper, for the first time, we propose a decentralized ABKS scheme with conjunctive keyword search for the cloud storage system. Besides the multi-keyword search in the decentralized setting, our scheme outsources the undesirable costly operations of decryption to the cloud without degrading the user's privacy. Furthermore, the encryption phase is also divided into two phases, an offline pre-computation phase which is independent with the plaintext message, access policy, and keyword set, and can be performed at any time when the data owner's device is otherwise not in use, and an online encryption phase which only incurs very little computation costs. Security analysis indicates that our scheme is provably secure in the random oracle model. The asymptotic complexity comparison and simulation results also show that our scheme achieves high computation efficiency. (C) 2019 Elsevier B.V. All rights reserved.
机译:近年来,云计算的越来越越来越大的普及导致数据所有者更愿意将其数据外包给云以享受按需存储和计算服务的趋势。对于安全和隐私问题,外包数据的细粒度访问控制和安全数据检索是至关重要的。基于属性的关键字搜索(ABK)方案,作为探索与关键字搜索(PEK)的公钥加密的概念到基于属性的加密(ABE)的上下文中的加密原语,可以使数据所有者灵活地共享他的数据对于满足访问策略的指定用户组,同时,维护敏感数据的机密性和可搜索属性。但是,在大多数先前的ABK方案中,未提供解密服务,并且需要一个完全信任的中央权限,这在访问策略在不同信任域和组织中发出的属性或凭据编写的场景中是不实际的。此外,存储和计算的效率也是ABKS方案实现的瓶颈。在本文中,我们首次提出了一个分散的ABKS方案,其中具有用于云存储系统的联合关键字搜索。除了分散的设置中的多关键字搜索之外,我们的方案除了降低用户的隐私后,我们的方案会使解密的解密的不良昂贵操作。此外,加密阶段也分为两个阶段,脱机预计算阶段与明文消息,访问策略和关键字集无关,并且可以在任何时间在任何时间不使用时执行,以及在线加密阶段,只会引发很少的计算成本。安全性分析表明我们的方案在随机的Oracle模型中被证实安全。渐近复杂性比较和仿真结果还表明,我们的方案实现了高计算效率。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号