摘要
针对云存储中敏感数据的机密性保护问题,在基于属性的加密基础上提出了一种密文访问控制方法HCRE。其思想是设计一种基于秘密共享方案的算法,将访问控制策略变更导致的重加密过程转移到云端执行,从而降低权限管理的复杂度,实现高效的动态密文访问控制。实验分析表明HCRE显著降低了权限管理的时间代价,而且没有向云端泄露额外的信息,保持了数据机密性。
To keep the data in the cloud confidential against unauthorized parties,a cryptographic access control solution called hybrid cloud re-encryption(HCRE) based on attribute-based encryption(ABE) was introduced.HCRE designed a secret sharing scheme to delegate the task of ABE re-encryption to the cloud service provider(CSP),which alleviates the administering burdens on the data owner.Experiments show that HCRE can handle dynamic access policies in a more ef-ficient way.Additionally,HCRE does not reveal extra information of the plaintext to the CSP,thus it does no harm to the data confidentiality.
出处
《通信学报》
EI
CSCD
北大核心
2011年第7期125-132,共8页
Journal on Communications
基金
国家高技术研究发展计划("863"计划)基金资助项目(2007AA120404)~~
关键词
云存储
云计算
密文访问控制
基于属性的加密
代理重加密
cloud storage
cloud computing
cryptographic access control
attributes-based encryption
proxy re-encryption