
公有云中针对服务提供商的用户隐私保护 被引量:1

User privacy protection against providers in public cloud computing
摘要 用户隐私保护一直是影响云计算推广的重要问题。当前,针对云服务提供商的用户隐私保护研究还只局限于少数特定领域,没有一个较为通用的方案。这严重阻碍了用户对云服务提供商及云计算服务模式的信任。为解决这一问题,首先分析了云环境中信息泄露的特点,并根据云计算服务及模型的特点,引出了一个让云服务各层或各模块相互分离、相互制约的用户隐私保护思路。随后沿用该思路,提出了一套基于Paa S层和Saa S层分离的完整隐私保护方案,让Paa S层和Saa S层服务有不同的云服务商分别提供,并让云服务商在提供服务的同时,根据相应规范限制对方泄露用户隐私。最后,对该方案进行了详细的安全性分析论证,并采用一个实际例子说明了该方案在保护用户隐私中的作用。该方案能在一般的云计算架构中实行,可通用于各类Saa S服务中,具有较强的理论和应用价值。 Protection of user privacy has always been important issues affecting cloud computing promotion. Currently, researches on user privacy protection for cloud service providers are rare and designed for specific areas and there is not a more common scenario. This seriously hampers the users' trust in the cloud service provider and cloud computing services. To resolve this problem, this paper begins with an analysis of the characteristics of information disclosure in a cloud envi- ronment, and puts forward an idea of making a cloud layer or module mutual isolated and restricted about user privacy protection, based on the features of cloud computing services and module. Based on this, it concludes with a set of full pri- vacy protection for PaaS and SaaS-based layer separation. Let different cloud service providers provide PaaS layer and SaaS layer services separately, and let cloud service providers limit the other disclosure of user privacy according to the corresponding specification when they provide service. Then it makes a detailed security analysis of the programme and utilizes an example to explain the role in user privacy protection. The cloud computing is implemented in the framework of the program in general and can pass for all kinds of SaaS services, with strong theoretical and applied value.
出处 《计算机工程与应用》 CSCD 北大核心 2015年第23期106-111,共6页 Computer Engineering and Applications
基金 国家自然科学基金(No.61070232 No.61272295 No.61105039)
关键词 公有云 云计算 云安全 软件即服务(Saa S) 隐私保护 public clouds cloud computing cloud security Software as a Service(SaaS) privacy protection
  • 相关文献


  • 1Subashini S,Kavitha V.A survey on security issues in service delivery models of cloud computing[J].Journal of Network and Computer Applications,2011,34(1):1-11.
  • 2Armbrust M,Fox A,Griffith R,et al.Above the clouds:Berkeley view of cloud computing,No.UCB/EECS22009228[R].Berkeley,USA:University of California at Berkeley,2009.
  • 3Zissis D,Lekkas D.Addressing cloud computing security issues[J].Future Generation Computer Systems,2012,3(3):583-592.
  • 4Kaufman L.Data security in the world of cloud computing[J].IEEE Security and Privacy,2009,7(4):61-64.
  • 5Sun Dawei,Chang Guiran,Sun Lina,et al.Surveying and analyzing security,privacy and trust issues in cloud computing environments[J].Procedia Engineering,2011,15:2852-2856.
  • 6Jansen W A.Cloud hooks:security and privacy issues in cloud computing[C]//Proceedings of the 44th Hawaii International Conference on System Sciences(HISCC-11),2011:1-10.
  • 7Agrawal D,El Abbadi A,Wang S.Secure and privacypreserving data services in the cloud:a data centric view[J].Proceedings of the VLDB Endowment,2012,8(5):2028-2029.
  • 8陈静,孙林夫.基于SaaS的产业链协作公共服务平台数据安全解决方案[J].计算机集成制造系统,2011,17(6):1317-1324. 被引量:19
  • 9Parakh A,Kak S.Online data storage using implicit security[J].Information Sciences,2009,179(19):3323-3331.
  • 10毛剑,李坤,徐先栋.云计算环境下隐私保护方案[J].清华大学学报(自然科学版),2011,51(10):1357-1362. 被引量:43


  • 1孙林夫.面向网络化制造的协同设计技术[J].计算机集成制造系统,2005,11(1):1-6. 被引量:47
  • 2赵慧娟,唐慧佳,孙林夫.基于应用服务提供商的汽车产业链协同商务平台解决方案[J].计算机集成制造系统,2006,12(5):745-752. 被引量:21
  • 3王大康,杜海山.信息安全中的加密与解密技术[J].北京工业大学学报,2006,32(6):497-500. 被引量:14
  • 4袁春,文振焜,张基宏,钟玉琢.基于密码学的访问控制和加密安全数据库[J].电子学报,2006,34(11):2043-2046. 被引量:11
  • 5ZHANG Qiang, CUI Dong. Enhance the user data privacy for SAAS by separation of data[C]//Proceedings of 2009 Interna- tional Conference on Information Management, Innovation Management and Industrial Engineering. Washington, D. C. , USA: IEEE Computer Society,2009 : 130- 132.
  • 6RSA private key encryption[EB/OL]. [2010-01-11]. http:// www. codeproject. com/KB/security/PrivateEncryption. as- px.
  • 7Parakh A, Kak S. Space efficient secret sharing for implicit data security [J]. Information Sciences, 2011, 181(2): 335 - 341.
  • 8Itani W, Kayssi A, Chehab A. Privacy as a service: Privacy-aware data storage and processing in cloud computing architectures [C]// Proceedings of the 8th IEEE International Conference on Dependable, Autonomic and Secure Computing. Chengdu, China: IEEE Computer Society, 2009:711-716.
  • 9Roy I, Ramadan H, Setty S, et al. Airavat: Security and privacy for map reduce [C]// Proceedings of the 7th USENIX Conference on Networked Systems Design and Implementation. San Jose, USA: USENIX Association Berkeley, 2010: 297 -312.
  • 10Mowbray M, Pearson S. A client based privacy manager for cloud computing [C]// Proceedings of the 4th International ICST Conference on Communication Syslem Software and Middleware. New York, USA: Association for Computing Machinery, 2009.












使用帮助 返回顶部