摘要
针对云存储服务中数据用户权限撤销粒度较粗及现有方案密钥分发计算量大等问题,基于双系统加密的思想,在合数阶双线性群上提出了一种新的细粒度权限撤销的安全云存储模型。数据拥有者同时也作为属性分发机构,保证了对自身数据的绝对控制,确保了在云服务商不可信情况下开放环境中的云端存储数据的安全。从模型架构和属性密钥分发两个方面对模型进行了研究,并用严格的数学方法证明了本方案是适应性安全的。云存储模型的数据访问策略根据实际需要可灵活设置,适用于云存储等开放式环境。
To solve the problem of coarse-grained attribute revocation for data users and huge computation for key distribution in the existing cloud storage model,we proposed a new secure model of cloud storage supporting fine-grained attribute revocation over the composite order bilinear groups.Data owner is also the attribute distributing authority,assuring the absolute control of the data in the cloud,which ensures that the data stored in open environment is secure on condition that the cloud service provider is unbelievable.We studied the model in two aspects,the frame of the model and the key distribution.The strict mathematical proofs of the model show that the scheme is adaptively secure.Based on the model,data access strategy is flexible and diverse,therefore it is suitable for open environment like cloud storage.
出处
《计算机科学》
CSCD
北大核心
2015年第7期210-215,共6页
Computer Science
基金
国家自然科学基金项目(61272486
61103231)
国家自然基金青年基金(61202489)
陕西省自然科学基础研究计划面上计划(2011JM8012)资助
关键词
属性加密
双系统加密
云存储
属性撤销
适应性安全
Attribute-based encryption
Dual-system encryption
Cloud storage
Attribute revocation
Adaptive security