计算机与现代化

• 信息安全 • 上一篇    下一篇

#br# 云存储中基于属性的密文策略访问控制方法

  

  1. (扬州大学信息工程学院,江苏扬州225009)
  • 收稿日期:2016-10-22 出版日期:2017-07-20 发布日期:2017-07-20
  • 作者简介:史庭俊(1963-),男,江苏扬州人,扬州大学信息工程学院副教授,博士,研究方向:无线传感器,信息安全; 张颖杰,女,江苏扬州人,硕士研究生,研究方向:无线传感器,信息安全。

Method of Access Control of Attribute-based Ciphertext Policy for Cloud Storage

  1. (College of Information Engineering, Yangzhou University, Yangzhou 225009, China)
  • Received:2016-10-22 Online:2017-07-20 Published:2017-07-20

摘要: 研究一种云存储中高效的基于属性加密的密文策略(Ciphertext-policy Attribute-based Encryption, CP-ABE)的访问控制方法。它采用非对称加密的方法加密数据,当撤销用户的属性时,授权产生新的属性组版本号密钥,交由云存储服务者再次加密密文,从而降低数据所有者的计算成本。由于本方案不需要更新用户私钥,因而减少了算法运算复杂度。通过相应的理论分析和实验表明,该方法在用户属性发生撤销时数据安全性较高。在降低授权计算负载和网络通信开销方面做了相应的贡献。

关键词: 云存储, 访问控制, 属性撤销, 重加密

Abstract: This paper puts forward an access control method with ciphertext-policy attribute-based encryption in cloud storage. It encrypts the data with asymmetric encryption. As the attribute of users is revoked, authority generates new version key of attribute group which is sent to the cloud to reencrypt the ciphertext so as to decrease the computing overload of data owner. Because this method doesnt need to update the private key of users, the complexity of algorithm is decreased. The theoretical analysis and experiment result show that this method performs well in the security of data as the attribute of users is revoked. In addition, the method also makes some contributions for reducing the computing overload of authority and transmission cost.

Key words: cloud storage, access control, revoke attributes, re-encryption

中图分类号: