Secure cloud storage using anonymous and blackbox traceable data access control

Secure cloud storage using anonymous and blackbox traceable data access control
复制标题

使用匿名和黑盒可追踪数据访问控制确保云存储安全

DOI:
10.1002/sec.1343
复制
发表时间:
2015-12
期刊:
Security and Communication System Security
影响因子:
--
通讯作者:
Yong Zhang
Yong Zhang
中科院分区:
其他
文献类型:
--
作者:
Songyang Wu;Yong Zhang

文献摘要

参考文献

相似文献

在云存储系统中,数据外包和服务提供商的不可信使得数据访问控制成为一个具有挑战性的问题,因为传统技术总是将服务提供商视为完全可信的一方。基于密文策略属性的加密CP-ABE在这种设置中显示出特别的优势,因为这种加密使数据所有者可以直接控制数据访问策略。然而,传统CP-ABE系统中的恶意用户可能会以解密设备/黑盒的形式泄露他们的解密密钥,而被抓住的风险很小,因为包括密钥管理机构在内的任何人都无法透露它们。这个问题已经成为许多数据外包应用中的主要实用问题,金融和医疗保健系统,在这些系统中,保护敏感数据的隐私至关重要。为了解决这个问题,黑盒可追踪的CP-ABE利用广播加密的“叛徒追踪”属性来识别这些恶意用户。然而,黑盒可追踪CP-ABE中的密钥和密文的大小取决于用户的数量。在本文中,我们介绍了一种基于累加器的加密ACC-ENC,它可以与传统的不可追溯的CP-ABE为基础的数据访问控制,以实现额外的黑盒可追溯性功能,而不牺牲性能,只是增加了O 1元素的密文和公钥。我们首先正式定义ACC-ENC的模型,并提出了一个具体的结构,被证明是完全安全的,然后,我们说明应用ACC-ENC获得基于CP-ABE的数据访问控制与黑盒可追溯性的云存储。性能评估表明,与原方案相比,该方案的额外计算量很小。版权所有© 2015约翰威利父子有限公司.
In cloud storage systems, data outsourcing and untrusted service providers make data-access control become a challenging issue because traditional technologies always consider service providers as a fully trusted party. Ciphertext-policy attribute-based encryption CP-ABE shows particular advantages in this setting because this encryption gives the data owner a direct control on data-access policies. However, malicious users in traditional CP-ABE systems may leak their decryption keys in the form of a decryption device/blackbox with little risk of getting caught because no one including the key authorities can reveal them. This issue has become a major practicality concern in many data outsourcing applications e.g., financial and healthcare systems where the preservation of privacy with regard to sensitive data is critical. To address this problem, blackbox traceable CP-ABE leveraged the "traitor tracing" property of broadcast encryption to identify these malicious users. However, the size of the keys and ciphertexts in the blackbox traceable CP-ABE depends on the number of users. In this paper, we introduce an accumulator-based encryption ACC-ENC, which can be integrated with conventional non-traceable CP-ABE-based data-access control to achieve an additional blackbox traceability feature without sacrificing performance just adds O1 elements to the ciphertext and the public key. We first formally define the model of ACC-ENC and present a concrete construction that is proven fully secure; then, we illustrate applying ACC-ENC to obtain CP-ABE-based data-access control with blackbox traceability for cloud storage. Performance evaluation shows that additional computation costs of the proposition are very low compared to the original scheme. Copyright © 2015 John Wiley & Sons, Ltd.
DOI: 10.1109/infcom.2010.5462174
发表时间: 2010-03
期刊: 2010 Proceedings IEEE INFOCOM
影响因子: --
作者:
Shucheng Yu;Cong Wang-;K. Ren;Wenjing Lou
通讯作者: Shucheng Yu;Cong Wang-;K. Ren;Wenjing Lou
DOI: 10.1007/3-540-44647-8_13
发表时间: 2001-08
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
D. Boneh;M. Franklin
通讯作者: D. Boneh;M. Franklin
DOI: 10.1145/1655008.1655020
发表时间: 2009-11
期刊: --
影响因子: --
作者:
Richard Chow;P. Golle;M. Jakobsson;E. Shi;J. Staddon;R. Masuoka;J. Molina
通讯作者: Richard Chow;P. Golle;M. Jakobsson;E. Shi;J. Staddon;R. Masuoka;J. Molina
DOI: 10.1007/978-3-642-31909-9_4
发表时间: 2011-09
期刊: --
影响因子: --
作者:
Saman Zarandioon;D. Yao;V. Ganapathy
通讯作者: Saman Zarandioon;D. Yao;V. Ganapathy
DOI: 10.1109/tpds.2010.203
发表时间: 2011-07-01
影响因子: 5.3
作者:
Hur, Junbeom;Noh, Dong Kun
通讯作者: Noh, Dong Kun