摘要
针对多域环境下电子文档安全管理,提出一种基于代理重加密机制的电子文档分发协议.该协议中引入代理服务器,由文档拥有者将数据加密后发送给半可信服务端,服务端对数据密文进行安全存储,同时对数据密文重加密后发送给用户.该方案避免了服务端对数据密文解密后进行二次加密,降低了服务端对电子文档管理的复杂度,同时采用密文方式存储,以防止服务器被恶意攻击后敏感数据泄露.与其他协议对比结果表明,新方案显著降低了代理重加密算法的计算复杂度,同时提高了加解密效率,保持了敏感数据机密性.
In view of the domain environment in E-documents management,an interoperable cross-domain distribution protocol for E-document is proposed.Based on proxy re-encryption,the scheme uses a semi-trusted entity called proxy server to re-encrypt the document ciphertext without decrypting the ciphertext,such that only users can decrypt the data with his private key.Compared with the existing system,the scheme relieves the server from intense encryption/decryption processing,and achieves reliable decentralized encryption/decryption with good scalability and efficiency.
出处
《北京邮电大学学报》
EI
CAS
CSCD
北大核心
2012年第5期81-84,共4页
Journal of Beijing University of Posts and Telecommunications
基金
国家重点基础研究发展计划项目(2007CB311203)
国家自然科学基金项目(60803157
90812001)
关键词
代理重加密
域分发
电子文档
re-encryption
multi-domain
E-documents distribution