Ensuring attribute privacy protection and fast decryption for outsourced data security in mobile cloud computing

Ensuring attribute privacy protection and fast decryption for outsourced data security in mobile cloud computing
复制标题

确保移动云计算外包数据安全属性隐私保护和快速解密

DOI:
10.1016/j.ins.2016.04.015
复制
发表时间:
2017-02
影响因子:
8.1
通讯作者:
Ilsun You
Ilsun You
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yinghui Zhang;Xiaofeng Chen;Jin Li;Duncan S. Wong;Hui Li;Ilsun You

文献摘要

参考文献

被引文献

相似文献

尽管许多用户将他们的各种数据外包给云,但数据安全和隐私问题仍然是阻碍云计算广泛采用的最大障碍。匿名属性加密(Anonymous ABE)支持对云存储进行细粒度的访问控制,并通过将属性信息隐藏在密文中来保护接收方的属性隐私。然而,在现有的匿名ABE工作中,用户只有在重复解密尝试后才知道属性和隐藏策略是否匹配。而且,每次解密通常需要许多对,并且计算开销随着访问公式的复杂性而增加。因此,现有方案存在严重的效率缺陷,不适合用户资源受限的移动云计算。在本文中,我们提出了一种新的技术,即先匹配后解密,在解密之前再引入匹配阶段。该技术通过计算密文中的特殊组件来工作,这些组件用于在不解密的情况下执行属性私钥是否与密文中的隐藏访问策略匹配的测试。为了快速解密,生成了特殊的属性密钥组件,允许在解密过程中聚合对。提出了一种基本的匿名ABE构造,并基于强存在不可伪造一次性签名获得了安全性增强的扩展。在所提出的结构中,属性匹配测试的计算成本小于一次解密操作,只需要少量且恒定的配对。正式的安全分析和性能比较表明,所提出的解决方案在保证属性隐私的同时,提高了移动云计算外包数据存储的解密效率。
Although many users outsource their various data to clouds, data security and privacy concerns are still the biggest obstacles that hamper the widespread adoption of cloud computing. Anonymous attribute-based encryption (anonymous ABE) enables fine-grained access control over cloud storage and preserves receivers’ attribute privacy by hiding attribute information in ciphertexts. However, in existing anonymous ABE work, a user knows whether attributes and a hidden policy match or not only after repeating decryption attempts. And, each decryption usually requires many pairings and the computation overhead grows with the complexity of the access formula. Hence, existing schemes suffer a severe efficiency drawback and are not suitable for mobile cloud computing where users may be resource-constrained.In this paper, we propose a novel technique called match-then-decrypt, in which amatching phaseis additionally introduced before thedecryption phase. This technique works by computing special components in ciphertexts, which are used to perform the test that if the attribute private key matches the hidden access policy in ciphertexts without decryption. For the sake of fast decryption, special attribute secret key components are generated which allow aggregation of pairings during decryption. We propose a basic anonymous ABE construction, and then obtain a security-enhanced extension based on strongly existentially unforgeable one-time signatures. In the proposed constructions, the computation cost of an attribute matching test is less than one decryption operation, which only needs small and constant number of pairings. Formal security analysis and performance comparisons indicate that the proposed solutions simultaneously ensure attribute privacy and improve decryption efficiency for outsourced data storage in mobile cloud computing.
DOI: 10.1007/978-3-319-26961-0_23
发表时间: 2015-12
期刊: --
影响因子: --
作者:
Payal Chaudhari;M. Das;A. Mathuria
通讯作者: Payal Chaudhari;M. Das;A. Mathuria
DOI: 10.1007/978-3-642-36362-7_11
发表时间: 2013-02
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
S. Hohenberger;Brent Waters
通讯作者: S. Hohenberger;Brent Waters
DOI: 10.1007/3-540-44647-8_13
发表时间: 2001-08
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
D. Boneh;M. Franklin
通讯作者: D. Boneh;M. Franklin
DOI: 10.1007/978-3-540-70936-7_29
发表时间: 2007-02
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
D. Boneh;Brent Waters
通讯作者: D. Boneh;Brent Waters
DOI: 10.1007/978-3-642-13013-7_2
发表时间: 2010-05
期刊: --
影响因子: --
作者:
Javier Herranz;Fabien Laguillaumie;Carla Ràfols
通讯作者: Javier Herranz;Fabien Laguillaumie;Carla Ràfols