【24h】

KP-ABE Based Verifiable Cloud Access Control Scheme

机译:基于KP-ABE的可验证云访问控制方案

获取原文
获取原文并翻译 | 示例

摘要

With the rapid development of mobile internet, mobile devices are requiring more complex authorization policy to ensure an secure access control on mobile data. However mobiles have limited resources (computing, storage, etc.) and are not suitable to execute complex operations. Cloud computing is an increasingly popular paradigm for accessing powerful computing resources. Intuitively we can solve that problem by moving the complex access control process to the cloud and implement a fine-grained access control relying on the powerful cloud. However the cloud computation may not be trusted, a crucial problem is how to verify the correctness of such computations. In this paper, we proposed a public verifiable cloud access control scheme based on Parno's public verifiable computation protocol. For the first time, we proposed the conception and concrete construction of verifiable cloud access control. Specifically, we firstly design a user private key revocable Key Policy Attribute Based Encryption (KP-ABE) scheme with non-monotonic access structure, which can be combined with the XACML policy perfectly. Secondly we convert the XACML policy into the access structure of KP-ABE. Finally we construct a security provable public verifiable cloud access control scheme based on the KP-ABE scheme we designed.
机译:随着移动互联网的飞速发展,移动设备需要更复杂的授权策略以确保对移动数据的安全访问控制。但是,移动设备的资源(计算,存储等)有限,并且不适合执行复杂的操作。云计算是访问功能强大的计算资源的一种日益流行的范例。直观地讲,我们可以通过将复杂的访问控制过程移至云中并依靠强大的云来实现细粒度的访问控制来解决该问题。但是云计算可能不可信,一个关键问题是如何验证此类计算的正确性。在本文中,我们提出了一种基于Parno的公共可验证计算协议的公共可验证云访问控制方案。我们首次提出了可验证的云访问控制的概念和具体构建。具体而言,我们首先设计了一种具有非单调访问结构的用户私钥可撤销的基于密钥策略属性的加密(KP-ABE)方案,该方案可以与XACML策略完美结合。其次,我们将XACML策略转换为KP-ABE的访问结构。最后,基于我们设计的KP-ABE方案,构建了一个可证明安全性的公共可验证云访问控制方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号