摘要
针对云计算环境下精细访问控制问题,提出一种基于属性加密的细粒度云访问控制(FGABE-CAC)方案,该方案设计新的多授权方系统模型,引入多权限树的思想和属性群加密的访问控制方法,允许数据拥有者按其自身需求定义不同的访问结构,制定精细的访问控制策略.通过多个授权方管理用户不同的属性域,并结合懒惰重加密和代理重加密技术,在用户权限撤销时实现高效的属性层面的撤销.最后给出方案的安全模型,并证明该方案在判定性双线性假设下是选择明文攻击安全的,具有前向安全性和后向安全性.仿真实验结果表明方案的正确性及高效性.
To solve the problem of fine-grained access control in cloud computing,a fine-grained attribute-based encryption cloud access control (FGABE-CAC)scheme is proposed.The scheme has a new system model with Multi-authorities.The notion of privilege tree and attribute group encryption into access control was built,which allowed data owners to define different access structure and fine-grained access control policies.Different attribute-fields of user were owned by Multi-authorities.When users ’ privileges were revoked,efficient attribute level revocation was put forward by lazy re-encryption and proxy re-encryption technology .In addition ,the security model was proposed and the scheme was proven to be the chosen plaintext attack(CPA)secure under the condition of decisional bilinear Diffie-Hellman(DBDH)assumption and it has forward and backward security.The simulation results show the correctness and efficiency of scheme.
出处
《微电子学与计算机》
CSCD
北大核心
2015年第9期33-39,44,共8页
Microelectronics & Computer
基金
国家自然科学基金(61462069)
内蒙古自然科学基金项目(2012MS0912
2014MS0622)
内蒙古教育厅高校科研项目(Njzy12110)
关键词
多授权
访问控制
权限树
属性群
multi-authorities
access control
privilege tree
attribute group