摘要
针对属性加解密过程中客户端计算开销大以及访问结构私密性未经保护等问题,提出一种基于密文策略的属性加密云数据高效访问控制方案.方案通过增加代理加解密服务器来减轻用户加解密计算开销并实现访问策略的隐藏;采用层次加密的思想来减轻数据加密的计算开销,即用对称密钥加密上传数据以保证效率,用属性密钥加密对称密钥以保证安全性;并通过设置授权用户集合来避免非授权用户的属性验证.实验分析表明,该方案与现有的访问控制方案相比,在加解密效率上有较大提升,有效缓解了客户机的加解密负担.
Aiming at the problems of the heavy client computing overhead for encryption and decryption and access structure privacy disclosure,an efficient CP-ABE (ciphertext policy-attribute based encryption) based access control scheme for cloud storage is pro- posed. By adding the proxy servers, the client computing overhead for encryption and decryption is greatly reduced and the access poli- cies can be hided;Hierarchical encryption is introduced to reduce the computing overhead for data encryption,in which the symmetric key is used to encrypt upload data for efficient and the attribute key is used to encrypt symmetric key for security ; By providing the au- thorized user set,the attribute set verification for unauthorized users can be avoided. The experiments show that,compared with the ex- isting access control schemes ,our scheme has higher encryption and decryption efficiency and clients' burden is effectively alleviated.
出处
《小型微型计算机系统》
CSCD
北大核心
2016年第10期2155-2161,共7页
Journal of Chinese Computer Systems
基金
国家"九七三"重点基础研究发展计划项目(2012CB315901)资助
关键词
云存储
访问控制
数据外包
属性加密
隐藏策略
cloud storage
access control
data outsourcing
attribute encryption
policy hiding