Multi-authority proxy re-encryption based on CPABE for cloud storage systems

Multi-authority proxy re-encryption based on CPABE for cloud storage systems
复制标题

基于CPABE的云存储系统多权限代理重加密

DOI:
10.1109/jsee
复制
发表时间:
2016-03
影响因子:
2.1
通讯作者:
ZHANG Yun
ZHANG Yun
中科院分区:
计算机科学3区
文献类型:
--
作者:
XU Xiaolong;ZHOU Jinglan;WANG Xinheng;ZHANG Yun

文献摘要

被引文献

相似文献

数据管理和数据所有权之间的分离使得云存储系统中的数据安全和隐私保护变得困难。传统的加密技术不适合云存储系统中的数据保护。提出了一种新的基于密文策略属性加密的多授权代理重加密机制(MPRE-CPABE)。MPRE-CPABE要求数据所有者将每个文件分为两个块,一个大块和一个小块。小块用于加密大块作为私钥,然后将加密后的大块上传到云存储系统。即使上传的大块文件被盗,非法用户也无法轻易获得文件的完整信息。基于密文策略的属性加密(CPABE)在分发密钥或撤销用户访问权限时存在严重的过载和不安全问题。MPRE-CPABE将CPABE应用到多权限云存储系统中,解决了上述问题。为了在多授权环境下支持多种细粒度的门限访问控制策略,降低密钥分发的计算开销,提出了加权访问结构(WAS).同时,MPRE-CPABE使用代理重新加密,以减少访问撤销的计算成本。实验在Ubuntu和CloudSim平台上实现。实验结果表明,MPRE-CPABE可以大大减少密钥组件生成和用户访问权限撤销的计算量。MPRE-CPABE在决策双线性Diffie-Hellman(DBDH)安全模型下也是安全的。
The dissociation between data management and data ownership makes it difficult to protect data security and privacy in cloud storage systems. Traditional encryption technologies are not suitable for data protection in cloud storage systems. A novel multi-authority proxy re-encryption mechanism based on ciphertext-policy attribute-based encryption (MPRE-CPABE) is proposed for cloud storage systems. MPRE-CPABE requires data owner to split each file into two blocks, one big block and one small block. The small block is used to encrypt the big one as the private key, and then the encrypted big block will be uploaded to the cloud storage system. Even if the uploaded big block of file is stolen, illegal users cannot get the complete information of the file easily. Ciphertext-policy attribute-based encryption (CPABE) is always criticized for its heavy overload and insecure issues when distributing keys or revoking user's access right. MPRE-CPABE applies CPABE to the multi-authority cloud storage system, and solves the above issues. The weighted access structure (WAS) is proposed to support a variety of fine-grained threshold access control policy in multi-authority environments, and reduce the computational cost of key distribution. Meanwhile, MPRE-CPABE uses proxy re-encryption to reduce the computational cost of access revocation. Experiments are implemented on platforms of Ubuntu and CloudSim. Experimental results show that MPRE-CPABE can greatly reduce the computational cost of the generation of key components and the revocation of user's access right. MPRE-CPABE is also proved secure under the security model of decisional bilinear Diffie-Hellman (DBDH).