摘要
云存储的应用环境中存在缺乏细粒度访问控制、密钥管理难度大、难以抵御合谋攻击等问题,为此提出了一种新的用于云存储的密文策略属性基加密(ciphertext-policy attribute-based encryption,CP-ABE)方案。通过引入由数据属主独立控制的许可属性,构建不同属性域的CP-ABE方案,能够防止云存储系统特权用户的内部攻击,使数据属主能完全控制其他共享用户对其云数据的访问。实验结果表明,该方案在提供安全性的同时能极大地提高用户属性撤销的效率。最后,对该方案进行了安全分析,并证明了该方案在DBDH假设下是CPA,安全的。
There exists some problems as the lack of fine-grained access control,low efficiency of key management and the vulnerability against collusion attack in the cloud storage environment,where there's a large number of users and files.This paper proposed a new CP-ABE scheme applied in cloud storage.It introduced the permission attributes managed by the data owners,and constructed different attribute field to resolve the security problem such as the inner attacks and data control.Se-veral experiments show that revocation method for user attributes performs wih high efficiency while providing security.In addition,it proves the scheme is secure against the chosen-plaintext attack(CPA) under the decision bilinear diffie hellman(DBDH) assumption.
出处
《计算机应用研究》
CSCD
北大核心
2012年第4期1452-1456,共5页
Application Research of Computers
关键词
云存储
访问控制
属性基加密
存储安全
cloud storage
access control
attribute-based encryption
storage security