Cross-group Secret Sharing for Secure Cloud Storage Service

Cross-group Secret Sharing for Secure Cloud Storage Service
复制标题

DOI:
10.1145/2857546.2857610
复制
发表时间:
2016-01
期刊:
Proceedings of the 10th International Conference on Ubiquitous Information Management and Communication
影响因子:
--
通讯作者:
Chenyutao Ke;Hiroaki Anada;Junpei Kawamoto;Kirill Morozov;K. Sakurai
Chenyutao Ke;Hiroaki Anada;Junpei Kawamoto;Kirill Morozov;K. Sakurai
中科院分区:
其他
文献类型:
--
作者:
Chenyutao Ke;Hiroaki Anada;Junpei Kawamoto;Kirill Morozov;K. Sakurai

文献摘要

相似文献

随着互联网的普及,许多移动的设备在我们的日常生活中使用,例如平板电脑和移动的电话。然后,个人数据通常保存在存储提供商的数据服务器上,如亚马逊,谷歌,雅虎,百度等。在这种情况下,秘密共享可以用于将个人数据存储到多个提供商上,同时降低数据丢失、数据泄露给未授权方以及数据伪造的风险。秘密共享是解决分布式存储系统中联合收割机安全性和可用性问题的方法之一。然而,很少有工作考虑服务器的从属关系,特别是,一个恶意的提供者可能会恢复秘密数据非法通过操纵服务器上持有足够的份额,以恢复秘密的问题。针对这一问题,本文提出了一个双门限秘密共享方案,以实现一种新的跨组策略。通过单向函数或一次性密码本将t-out-of-m提供者的秘密共享方案和k-out-of-n服务器的秘密共享方案相结合,构造了一个强制从m个组中收集k个共享的方案。与以前的工作相比,我们的计划可以实现的功能,主动更新的份额和添加新的份额与简单的计算。
With the spread of the Internet, many mobile devices are used in our daily lives, such as tablets and mobile phones. Then, personal data are often saved on data servers of the storage providers such as Amazon, Google, Yahoo, Baidu and others. In this context, the secret sharing can be used to store personal data onto several providers, simultaneously reducing the risk of data loss, the data leakage to unauthorized parties, and data falsification. Secret sharing is one of the solutions to combine security and availability in the distributed storage. However, few works considered servers' affiliations, and specifically, the problem that a malicious provider may recover secret data illegally through manipulation on servers that hold enough shares to recover the secret. In this paper, to resolve the problem, we propose a two-threshold secret sharing scheme in order to enforce a new type of cross-group policy. By combining t-out-of-m providers' secret sharing scheme and a k-out-of-n servers' secret sharing scheme via an one-way function or an one-time pad, we construct a scheme that forces k shares to be collected from m groups. Compared with previous work, our scheme can attain the functionalities of proactively updating shares and adding new shares with simple computation.