A Hybrid Scheme for Fine-Grained Search and Access Authorization in Fog Computing Environment

A Hybrid Scheme for Fine-Grained Search and Access Authorization in Fog Computing Environment
复制标题

雾计算环境中细粒度搜索和访问授权的混合方案

DOI:
10.3390/s17061423
复制
发表时间:
2017-06
期刊:
影响因子:
3.9
通讯作者:
Mingda Jiang
Mingda Jiang
中科院分区:
综合性期刊3区
文献类型:
--
作者:
Min Xiao;Jing Zhou;Xuejiao Liu;Mingda Jiang

文献摘要

参考文献

被引文献

相似文献

在雾计算环境中,加密的敏感数据可能会传输到网络边缘的多个雾节点,以实现低延迟;因此,雾节点需要作为云服务器对加密数据进行搜索。由于雾节点倾向于为通常在资源受限的终端设备上运行的物联网应用提供服务,因此有必要设计轻量级解决方案。目前,对这一问题的研究还不多。针对资源受限的终端用户,提出了一种跨用户-雾-云的细粒度所有者强制数据搜索和访问授权方案.与现有方案相比,该方案同时支持索引加密和细粒度访问控制,并且索引密文和数据密文基于一个CP-ABE原语构造,共享相同的密钥对,从而显著提高了数据访问效率,大大降低了密钥管理的成本。此外,该方案允许资源受限的终端设备在线快速组装密文,并将大部分解密任务安全地外包给fog节点,同时采用中介加密机制实现即时用户撤销,而不是在多个fog节点上重新加密多个副本的密文。安全性和性能分析表明,我们的方案适合雾计算环境。
In the fog computing environment, the encrypted sensitive data may be transferred to multiple fog nodes on the edge of a network for low latency; thus, fog nodes need to implement a search over encrypted data as a cloud server. Since the fog nodes tend to provide service for IoT applications often running on resource-constrained end devices, it is necessary to design lightweight solutions. At present, there is little research on this issue. In this paper, we propose a fine-grained owner-forced data search and access authorization scheme spanning user-fog-cloud for resource constrained end users. Compared to existing schemes only supporting either index encryption with search ability or data encryption with fine-grained access control ability, the proposed hybrid scheme supports both abilities simultaneously, and index ciphertext and data ciphertext are constructed based on a single ciphertext-policy attribute based encryption (CP-ABE) primitive and share the same key pair, thus the data access efficiency is significantly improved and the cost of key management is greatly reduced. Moreover, in the proposed scheme, the resource constrained end devices are allowed to rapidly assemble ciphertexts online and securely outsource most of decryption task to fog nodes, and mediated encryption mechanism is also adopted to achieve instantaneous user revocation instead of re-encrypting ciphertexts with many copies in many fog nodes. The security and the performance analysis show that our scheme is suitable for a fog computing environment.
DOI: 10.1007/11836810_16
发表时间: 2006-08
期刊: --
影响因子: --
作者:
J. Baek;R. Safavi-Naini;W. Susilo
通讯作者: J. Baek;R. Safavi-Naini;W. Susilo
DOI: 10.1007/978-3-642-00306-6_11
发表时间: 2009-02
期刊: Molecular cell
影响因子: 16
作者:
Peishun Wang;Huaxiong Wang;J. Pieprzyk
通讯作者: Peishun Wang;Huaxiong Wang;J. Pieprzyk
DOI: 10.1016/j.future.2017.01.026
发表时间: 2018-01-01
影响因子: 7.5
作者:
Jiang, Yinhao;Susilo, Willy;Guo, Fuchun
通讯作者: Guo, Fuchun
DOI: 10.3233/jcs-2009-0383
发表时间: 2010-01-01
影响因子: 1.2
作者:
Pirretti, Matthew;Traynor, Patrick;Waters, Brent
通讯作者: Waters, Brent
DOI: 10.3233/jcs-2011-0426
发表时间: 2011-01-01
影响因子: 1.2
作者:
Curtmola, Reza;Garay, Juan;Ostrovsky, Rafail
通讯作者: Ostrovsky, Rafail