TMACS: A Robust and Verifiable Threshold Multi-Authority Access Control System in Public Cloud Storage

TMACS: A Robust and Verifiable Threshold Multi-Authority Access Control System in Public Cloud Storage
复制标题

TMACS:公有云存储中稳健且可验证的阈值多权限访问控制系统

DOI:
10.1109/tpds.2015.2448095
复制
发表时间:
2016-05-01
影响因子:
5.3
通讯作者:
Hong, Jianan
Hong, Jianan
中科院分区:
计算机科学2区
文献类型:
--
作者:
Li, Wei;Xue, Kaiping;Hong, Jianan

文献摘要

被引文献

相似文献

基于属性的加密(ABE)被认为是一种很有前途的加密工具,可以保证数据所有者对其在公共云存储中的数据的直接控制。早期的ABE方案只涉及一个权威机构来维护整个属性集,这会在安全性和性能上带来单点瓶颈。随后,提出了一些多权威方案,其中多个权威分别维护不相交的属性子集。然而,单点瓶颈问题仍未解决。本文从另一个角度提出了一种面向公有云存储的门限多权限CP-ABE访问控制方案TMACS,多个权限共同管理一个统一的属性集。在TMACS中,利用(t,n)门限秘密共享机制,主密钥可以在多个权威机构之间共享,法律的用户可以通过与任意t个权威机构交互来生成自己的密钥。安全性和性能分析结果表明,TMACS不仅在少于t个授权者被泄露时是可验证安全的,而且在系统中存在不少于t个授权者时也是鲁棒的。此外,通过将传统的多权限方案与TMACS有效结合,构造了一种混合方案,该方案既满足属性来自不同权限的场景,又具有安全性和系统级鲁棒性。
Attribute-based Encryption (ABE) is regarded as a promising cryptographic conducting tool to guarantee data owners' direct control over their data in public cloud storage. The earlier ABE schemes involve only one authority to maintain the whole attribute set, which can bring a single-point bottleneck on both security and performance. Subsequently, some multi-authority schemes are proposed, in which multiple authorities separately maintain disjoint attribute subsets. However, the single-point bottleneck problem remains unsolved. In this paper, from another perspective, we conduct a threshold multi-authority CP-ABE access control scheme for public cloud storage, named TMACS, in which multiple authorities jointly manage a uniform attribute set. In TMACS, taking advantage of (t,n) threshold secret sharing, the master key can be shared among multiple authorities, and a legal user can generate his/her secret key by interacting with any t authorities. Security and performance analysis results show that TMACS is not only verifiable secure when less than t authorities are compromised, but also robust when no less than t authorities are alive in the system. Furthermore, by efficiently combining the traditional multi-authority scheme with TMACS, we construct a hybrid one, which satisfies the scenario of attributes coming from different authorities as well as achieving security and system-level robustness.