Dynamic Secure Cloud Storage with Provenance

Dynamic Secure Cloud Storage with Provenance
复制标题

DOI:
10.1007/978-3-642-28368-0_28
复制
发表时间:
2012
期刊:
--
影响因子:
--
通讯作者:
Sherman S. M. Chow;Cheng-Kang Chu;Xinyi Huang;Jianying Zhou;R. Deng
Sherman S. M. Chow;Cheng-Kang Chu;Xinyi Huang;Jianying Zhou;R. Deng
中科院分区:
其他
文献类型:
--
作者:
Sherman S. M. Chow;Cheng-Kang Chu;Xinyi Huang;Jianying Zhou;R. Deng

文献摘要

被引文献

相似文献

使用云存储的一个问题是,敏感数据应该对数据所有者信任域之外的服务器保密。另一个问题是,用户可能希望在共享或访问数据时保持他/她的匿名性(例如在Web 2.0应用程序中)。为了充分享受云存储的好处,我们需要一个细粒度的机密数据共享机制(可以指定谁可以访问他/她的加密文件的哪些类别),动态(用户总数在设置中不是固定的,任何新用户都可以解密以前加密的消息),可扩展(空间要求不取决于解密器的数量),负责(必要时可撤销匿名)和安全(信任级别最小化),提出了一种支持动态用户和数据来源的安全云存储系统。先前的系统基于特定的构造,并且不提供所有上述期望的特性。最重要的是,不支持动态用户。我们研究了密码匿名认证和加密机制提供的各种功能,并实例化我们的设计与验证本地可验证的群签名和基于身份的广播加密与恒定大小的密文和私钥。为了实现我们的概念,我们配备了动态密文更新功能的广播加密,并给出形式化的安全保证,以适应选择密文解密和更新攻击。
One concern in using cloud storage is that the sensitive data should be confidential to the servers which are outside the trust domain of data owners. Another issue is that the user may want to preserve his/her anonymity in the sharing or accessing of the data (such as in Web 2.0 applications). To fully enjoy the benefits of cloud storage, we need a confidential data sharing mechanism which is fine-grained (one can specifywhocan accesswhich classesof his/her encrypted files), dynamic (the total number of users is not fixed in the setup, and any new user can decrypt previously encrypted messages), scalable (space requirement does not depend on the number of decryptors), accountable (anonymity can be revoked if necessary) and secure (trust level is minimized).This paper addresses the problem of building a secure cloud storage system which supports dynamic users and data provenance. Previous system is based on specific constructions and does not offer all of the aforementioned desirable properties. Most importantly, dynamic user is not supported. We study the various features offered by cryptographic anonymous authentication and encryption mechanisms; and instantiate our design with verifier-local revocable group signature and identity-based broadcast encryption with constant size ciphertexts and private keys. To realize our concept, we equip the broadcast encryption with the dynamic ciphertext update feature, and give formal security guarantee against adaptive chosen-ciphertext decryption and update attacks.