摘要
文中针对云环境下用户隐私数据的安全性和数据应用操作效率要求相矛盾的问题,提出一种基于同态加密和密钥策略基于属性的加密(Ciphertext-Policy Attributed-Based Encryption,CP-ABE)混合加密方案,实现了对云用户隐私信息分类加密保护。方案中将云用户隐私数据分为绝对保密的A类和可被部分可信用户合理访问的B类两种,其中A类数据进行同态方法加密,确保重要的隐私不容易被窃取;对B类数据使用CP-ABE算法进行加密,并制定访问控制树,确保可信用户进行合理访问。实验结果表明,通过基于不同类别的加密方案,使得云用户的数据共享更加安全便捷,混合方案更贴近用户需求。
Due to the paradox between the security of user privacy data and the efficiency of application operation,a scheme combined the homomorphic encryption with the CP-ABE encryption is proposed.Firstly,the user privacy is divided into A-class and B-class. The A-class privacy is strictly private data and the B-class privacy can be visited by other trusted users. The homomorphic encryption is used for the A-class privacy to ensure the important data which cannot be visited. Then,CP-ABE encryption is used for the B-class privacy and the access control tree which can be visited is built. Experimental results show that the different encryption policies for different privacies could make the cloud user data safer and the combined solution is close to the user requirements.
出处
《南京邮电大学学报(自然科学版)》
北大核心
2015年第5期80-86,共7页
Journal of Nanjing University of Posts and Telecommunications:Natural Science Edition
基金
国家自然科学基金(61170065
61373017)
中国博士后基金(2013M541702)
江苏省未来网络(BY2013095-4-03)
江苏省自然科学基金青年基金(BK20130876)
广东省普及型高性能计算机重点实验室/深圳市服务计算与应用重点实验室开放课题(TK215001)资助项目
关键词
云计算
隐私保护
同态加密
CP-ABE
cloud computing
privacy protection
homomorphic encryption
CP-ABE