Efficient revocation in ciphertext-policy attribute-based encryption based cryptographic cloud storage

Efficient revocation in ciphertext-policy attribute-based encryption based cryptographic cloud storage
复制标题

DOI:
10.1631/jzus.c1200240
复制
发表时间:
2013-02
期刊:
Journal of Zhejiang University SCIENCE C
影响因子:
--
通讯作者:
Yong Cheng;Zhiying Wang;Jun Ma;Jiangjiang Wu;Songzhu Mei;Jiangchun Ren
Yong Cheng;Zhiying Wang;Jun Ma;Jiangjiang Wu;Songzhu Mei;Jiangchun Ren
中科院分区:
其他
文献类型:
--
作者:
Yong Cheng;Zhiying Wang;Jun Ma;Jiangjiang Wu;Songzhu Mei;Jiangchun Ren

文献摘要

被引文献

相似文献

客户在加密云存储中存储和共享其敏感数据是安全的。然而,在密码访问控制系统中,撤销操作无疑是一个性能杀手。为了优化撤销过程,我们提出了一个新的有效的撤销方案,这是高效,安全,和无人协助。该方案首先将原始数据划分为若干切片,然后发布到云存储中。当撤销发生时,数据所有者只需要检索一个切片,并重新加密和重新发布它。因此,通过只影响一个切片而不是整个数据来加速撤销过程。我们已经将有效的撤销方案应用于基于密文策略属性加密(CP-ABE)的密码云存储。安全性分析表明,我们的方案是计算安全的。理论评估和实验测试结果表明,有效的撤销方案可以减少数据所有者的工作量,如果撤销频繁发生。
It is secure for customers to store and share their sensitive data in the cryptographic cloud storage. However, the revocation operation is a sure performance killer in the cryptographic access control system. To optimize the revocation procedure, we present a new efficient revocation scheme which is efficient, secure, and unassisted. In this scheme, the original data are first divided into a number of slices, and then published to the cloud storage. When a revocation occurs, the data owner needs only to retrieve one slice, and re-encrypt and re-publish it. Thus, the revocation process is accelerated by affecting only one slice instead of the whole data. We have applied the efficient revocation scheme to the ciphertext-policy attribute-based encryption (CP-ABE) based cryptographic cloud storage. The security analysis shows that our scheme is computationally secure. The theoretically evaluated and experimentally measured performance results show that the efficient revocation scheme can reduce the data owner’s workload if the revocation occurs frequently.