摘要
为解决云存储强安全性要求(即云端也是不可信的情况)下的数据安全问题,提出一个基于引导密钥广播加密的云存储系统方案。基于引导密码加密的方法来解决传统的加密中密钥难以管理的问题;在存储数据到云端的过程中,采用基于身份的广播加密的方法保证合法资源用户的安全共享;进一步提出由文件所有者掌握引导密钥来生成所需要的广播加密密钥的云存储方案,确保了用户数据的强安全性;给出了数据存储过程中的审计问责机制。分析结果表明了该算法具有较高的安全性和灵活性。
To solve the data security issues of the cloud storage system in the situation of strong security requirements (i. e. when the cloud is not credible), a cloud storage scheme based on boot password and broadcast encryption is proposed. Firstly, a new encryption based on boot password is given which can solve the difficulty of the key management of the traditional cryptographic algorithm. Secondly, in the process of storing data into the cloud, an identity-based broadcast encryption method is adopted to ensure safe sharing of resources for the legitimate users. Further, it proposed a cloud storage solution based on the above boot password and broadcast encryption of which the encrypted key is generated by the boot password mastered by the owner of the files, and the solution ensures that the file data is of strong security. Finally, the audit and accountability of the stored data are given. Analysis shows that the proposed algorithm has higher security and flexibility.
出处
《计算机工程与设计》
CSCD
北大核心
2013年第12期4167-4171,4177,共6页
Computer Engineering and Design
关键词
云存储
数据安全
引导密钥
广播加密
审计
cloud storage
data security
boot password
broadcast encryption
audit