计算机与现代化 ›› 2021, Vol. 0 ›› Issue (10): 119-126.

• 网络与通信 • 上一篇    

增强安全的云存储数据访问控制方案

  

  1. (1.重庆医科大学附属第一医院信息中心,重庆400016;2.重庆市生态环境大数据应用中心,重庆401147;
    3.重庆大学计算机学院,重庆400044)
  • 出版日期:2021-10-14 发布日期:2021-10-14
  • 作者简介:刘铮(1981—),男,重庆人,助理工程师,硕士,研究方向:网络安全,E-mail: leolau12@163.com; 吴柯桦(1990—),男,重庆人,工程师,硕士,研究方向:网络安全,E-mail: wukehua07@hotmail.com; 叶春晓(1973—),男,重庆人,教授,博士,研究方向:访问控制,数据库技术,软件工程,E-mail: yecx@cqu.edu.cn。
  • 基金资助:
    重庆医科大学附属第一医院院内管理科研基金重点项目(GLJJ2020-04); 重庆市科卫联合医学科研项目(2021MSXM147)

Security-enhanced Data Access Control for Multi-authority Cloud Storage

  1. (1. Information Center, The First Affiliated Hospital of Chongqing Medical University, Chongqing 400016, China;

    2. Chongqing Ecological Environment Big Data Application Center, Chongqing 401147, China;
    3. College of Computer Science, Chongqing University, Chongqing 400044, China)

  • Online:2021-10-14 Published:2021-10-14

摘要: 云存储带来了许多优势,例如,可节省用户的硬件购买成本,并提供实时在线数据存储服务。越来越多的人选择将数据存储在云上。为了提高数据安全性和数据隐私性,Wu等人在Yang的方案的基础上,给出了一种扩展的多权限云存储数据访问控制方案(NEDAC-MACS)。本文给出一种攻击方法,以证明被撤消的用户仍然可以解密NEDAC-MACS中的新密文,并提出一种增强NEDAC-MACS安全性的方案,该方案可以抵抗云服务器与用户之间的串通攻击。加密分析表明,该方案能够抵抗串通攻击并且是可行的。

关键词: 访问控制, 数据安全性, 合谋攻击, 云存储

Abstract: Cloud storage has brought many advantages, such as saving users hardware purchase costs and providing real-time online data storage services. More and more people are choosing to store data on the cloud. In order to improve data security and data privacy, Wu et al. gave an extended data access control scheme for multi-authority cloud storage (NEDAC-MACS) on the basis of the scheme of Yang. In this paper, an attack method is given to demonstrate that a revoked user can still decrypt new ciphertexts in NEDAC-MACS, and a scheme to enhance the security of NEDAC-MACS is proposed, which can resist the collusion attack between cloud server and users. Cryptographic analyses confirm that the scheme is able to resist collusion attacks and is feasible.

Key words: access control, data security, collusion attack, cloud storage