How to implement secure cloud file sharing using optimized attribute-based access control with small policy matrix and minimized cumulative errors

How to implement secure cloud file sharing using optimized attribute-based access control with small policy matrix and minimized cumulative errors
复制标题

如何使用优化的基于属性的访问控制、小策略矩阵和最小化累积错误来实现安全的云文件共享

DOI:
10.1016/j.cose.2021.102318
复制
发表时间:
2021-05
影响因子:
5.6
通讯作者:
Rongquan Feng
Rongquan Feng
中科院分区:
计算机科学3区
文献类型:
--
作者:
E Chen;Yan Zhu;Guizhen Zhu;Kaitai Liang;Rongquan Feng

文献摘要

参考文献

相似文献

通过云文件共享(CFS)的互联网用户的惊人增长引起了人们对前所未有的云安全和隐私泄露的担忧。此外,最近量子计算的突破进一步强化了这种担忧,因此我们在CFS服务中开发了一种有效的解决方案来保障个人隐私并抵御量子攻击。在我们的解决方案中,我们集成了基于属性的访问控制/可扩展访问控制标记。语言(ABAC/XACML)模型和密文-策略基于属性的加密(cabe)。为了提高CP-ABE的性能,我们利用一种优化方法将ABAC/XACML策略转换成一个小策略矩阵(SPM)。我们进一步证明了该矩阵具有较小的系数,并生成了一个全一重构向量,从而使格密码系统的累积误差减小到最小。利用SPM,我们设计了一种新的基于Lattice的CP-ABE方案(CP-ABE- l),以防止误差界的扩大。给出了满足三个格生成条件的系统参数的最优估计,以实现有效的误差比例分配(EPA)。在标准模型中的错误决策学习(DLWE)假设下,我们的方案被证明是安全的,可以抵抗选择明文攻击。性能评估和分析表明,该方案不仅参数短,而且保持了高效的计算和合理的存储过载。
The stunning growth of Internet users through Cloud File Sharing (CFS) is raising great concerns about unprecedented cloud security and privacy breach. Also, the recent breakthrough in quantum computing further reinforces this kind of concerns, thus we exploit an efficient solution to guarantee personal privacy and resist quantum attacks in the CFS service. In our solution, we integrate the Attribute-based Access Control/eXtensible Access Control Markup.Language (ABAC/XACML) model and the Ciphertext-Policy Attribute-Based Encryption (CPABE) into the CFS. To improve the performance of CP-ABE, we make use of an optimization method to convert the ABAC/XACML policy into a Small Policy Matrix (SPM). We further prove that this matrix has small coefficients and generates an all-one reconstruction vector, such that it reduces the cumulative error in lattice cryptosystem to the minimum. By using the SPM, we design a new CP-ABE scheme from Lattice (CP-ABE-L) to prevent the enlargement of error bounds.We also give the optimal estimation of system parameters, which satisfy three lattice-generation conditions to implement a valid Error Proportion Allocation (EPA). Our scheme is proved secure against chosen-plaintext attack with a selective attribute set under the Decision Learning with Errors (DLWE) assumption in the standard model. The performance evaluation and analyses illustrate that our scheme not only has short parameters, but also maintains efficient computation and reasonable storage overloads.
DOI: 10.1007/978-3-642-30057-8_17
发表时间: 2012-05
期刊: --
影响因子: --
作者:
Shweta Agrawal;Xavier Boyen;V. Vaikuntanathan;Panagiotis Voulgaris;H. Wee
通讯作者: Shweta Agrawal;Xavier Boyen;V. Vaikuntanathan;Panagiotis Voulgaris;H. Wee
DOI: 10.1007/978-3-642-13013-7_2
发表时间: 2010-05
期刊: --
影响因子: --
作者:
Javier Herranz;Fabien Laguillaumie;Carla Ràfols
通讯作者: Javier Herranz;Fabien Laguillaumie;Carla Ràfols
DOI: 10.1145/3292548
发表时间: 2019-02-01
影响因子: 16.6
作者:
Nejatollahi, Hamid;Dutt, Nikil;Cammarota, Rosario
通讯作者: Cammarota, Rosario
DOI: 10.1109/tpds.2010.203
发表时间: 2011-07-01
影响因子: 5.3
作者:
Hur, Junbeom;Noh, Dong Kun
通讯作者: Noh, Dong Kun
DOI: 10.1007/978-3-319-93387-0_27
发表时间: 2018-07
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Joseph K. Liu;Tsz Hon Yuen;Peng Zhang;K. Liang
通讯作者: Joseph K. Liu;Tsz Hon Yuen;Peng Zhang;K. Liang