SeDaSC: Secure Data Sharing in Clouds

SeDaSC: Secure Data Sharing in Clouds
复制标题

DOI:
10.1109/jsyst.2014.2379646
复制
发表时间:
2017-06-01
影响因子:
4.4
通讯作者:
Zomaya, Albert Y.
Zomaya, Albert Y.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Ali, Mazhar;Dhamotharan, Revathi;Zomaya, Albert Y.

文献摘要

被引文献

相似文献

云存储是云的应用,该云使组织无法建立内部数据存储系统。但是,云存储引起了安全问题。如果存在组共享的数据,则数据既面临云特异性和常规内幕威胁。在反对内部人士威胁合法但恶意用户的威胁的小组中,安全数据共享是一个重要的研究问题。在本文中,我们提出了提供:1)数据机密性和完整性的云(SEDASC)方法中的安全数据共享; 2)访问控制; 3)数据共享(转发)无需使用计算密集的重新加密; 4)内部威胁安全; 5)向前和向后访问控制。 SEDASC方法论使用单个加密密钥对文件进行加密。为每个用户生成了两个不同的密钥共享,用户只能获得一个共享。拥有一份钥匙的一部分使Sedasc方法论可以应对内幕威胁。另一个密钥共享由受信任的第三方存储,该份额称为加密服务器。 SEDASC方法适用于常规和移动云计算环境。我们实施了SEDASC方法论的工作原型,并根据各种操作期间消耗的时间来评估其性能。我们通过使用高级Petri网,可满足模型理论库和Z3求解器正式验证SEDASC的工作。事实证明,结果令人鼓舞,并表明SEDASC有可能有效地用于云中的安全数据共享。
Cloud storage is an application of clouds that liberates organizations from establishing in-house data storage systems. However, cloud storage gives rise to security concerns. In case of group-shared data, the data face both cloud-specific and conventional insider threats. Secure data sharing among a group that counters insider threats of legitimate yet malicious users is an important research issue. In this paper, we propose the Secure Data Sharing in Clouds (SeDaSC) methodology that provides: 1) data confidentiality and integrity; 2) access control; 3) data sharing (forwarding) without using compute-intensive reencryption; 4) insider threat security; and 5) forward and backward access control. The SeDaSC methodology encrypts a file with a single encryption key. Two different key shares for each of the users are generated, with the user only getting one share. The possession of a single share of a key allows the SeDaSC methodology to counter the insider threats. The other key share is stored by a trusted third party, which is called the cryptographic server. The SeDaSC methodology is applicable to conventional and mobile cloud computing environments. We implement a working prototype of the SeDaSC methodology and evaluate its performance based on the time consumed during various operations. We formally verify the working of SeDaSC by using high-level Petri nets, the Satisfiability Modulo Theories Library, and a Z3 solver. The results proved to be encouraging and show that SeDaSC has the potential to be effectively used for secure data sharing in the cloud.