K2C: Cryptographic Cloud Storage with Lazy Revocation and Anonymous Access

K2C: Cryptographic Cloud Storage with Lazy Revocation and Anonymous Access
复制标题

DOI:
10.1007/978-3-642-31909-9_4
复制
发表时间:
2011-09
期刊:
--
影响因子:
--
通讯作者:
Saman Zarandioon;D. Yao;V. Ganapathy
Saman Zarandioon;D. Yao;V. Ganapathy
中科院分区:
其他
文献类型:
--
作者:
Saman Zarandioon;D. Yao;V. Ganapathy

文献摘要

被引文献

相似文献

安全和隐私问题阻碍了云存储和计算在敏感环境中的采用。我们提出了一种以用户为中心的隐私保护加密访问控制协议,称为 K2C(Key To Cloud),使最终用户能够在不受信任的云存储中匿名安全地存储、共享和管理其敏感数据。K2C 具有可扩展性并支持延迟撤销。它可以在现有云服务和 API 之上轻松实现 - 我们展示了基于 Amazon S3 API 的原型。K2C 是通过我们新的加密密钥更新方案(称为 AB−HKU)实现的。 AB−HKU 方案的主要优点是它支持有效的层次结构权限委托和撤销,而不需要复杂的加密数据结构。我们分析访问控制协议的安全性和性能,并提供开源实现。本项目中开发的两个加密库,即基于身份的分层加密和基于密钥策略属性的加密,其用途超出了所研究的特定云安全问题。
Security and privacy concerns hinder the adoption of cloud storage and computing in sensitive environments. We present a user-centric privacy-preserving cryptographic access control protocol calledK2C(Key To Cloud) that enables end-users to securely store, share, and manage their sensitive data in an untrusted cloud storage anonymously.K2Cis scalable and supports the lazy revocation. It can be easily implemented on top of existing cloud services and APIs – we demonstrate its prototype based on Amazon S3 API.K2Cis realized through our new cryptographic key-updating scheme, referred to asAB−HKU. The main advantage of theAB−HKUscheme is that it supports efficient delegation and revocation of privileges for hierarchies without requiring complex cryptographic data structures. We analyze the security and performance of our access control protocol, and provide an open source implementation. Two cryptographic libraries, Hierarchical Identity-Based Encryption and Key-Policy Attribute-Based Encryption, developed in this project are useful beyond the specific cloud security problem studied.