...
首页> 外文期刊>IEEE transactions on information forensics and security >RAAC: Robust and Auditable Access Control With Multiple Attribute Authorities for Public Cloud Storage
【24h】

RAAC: Robust and Auditable Access Control With Multiple Attribute Authorities for Public Cloud Storage

机译:RAAC:具有公共属性的多属性授权的健壮且可审核的访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

Data access control is a challenging issue in public cloud storage systems. Ciphertext-policy attribute-based encryption (CP-ABE) has been adopted as a promising technique to provide flexible, fine-grained, and secure data access control for cloud storage with honest-but-curious cloud servers. However, in the existing CP-ABE schemes, the single attribute authority must execute the time-consuming user legitimacy verification and secret key distribution, and hence, it results in a single-point performance bottleneck when a CP-ABE scheme is adopted in a large-scale cloud storage system. Users may be stuck in the waiting queue for a long period to obtain their secret keys, thereby resulting in low efficiency of the system. Although multi-authority access control schemes have been proposed, these schemes still cannot overcome the drawbacks of single-point bottleneck and low efficiency, due to the fact that each of the authorities still independently manages a disjoint attribute set. In this paper, we propose a novel heterogeneous framework to remove the problem of single-point performance bottleneck and provide a more efficient access control scheme with an auditing mechanism. Our framework employs multiple attribute authorities to share the load of user legitimacy verification. Meanwhile, in our scheme, a central authority is introduced to generate secret keys for legitimacy verified users. Unlike other multi-authority access control schemes, each of the authorities in our scheme manages the whole attribute set individually. To enhance security, we also propose an auditing mechanism to detect which attribute authority has incorrectly or maliciously performed the legitimacy verification procedure. Analysis shows that our system not only guarantees the security requirements but also makes great performance improvement on key generation.
机译:在公共云存储系统中,数据访问控制是一个具有挑战性的问题。基于密文策略的基于属性的加密(CP-ABE)已被用作一种有前途的技术,可为诚实但又好奇的云服务器提供灵活,细粒度和安全的数据访问控制,以用于云存储。但是,在现有的CP-ABE方案中,单属性授权机构必须执行耗时的用户合法性验证和秘密密钥分配,因此,当在一个CP-ABE方案中采用CP-ABE方案时,这会导致单点性能瓶颈。大型云存储系统。用户可能长时间停留在等待队列中以获得他们的秘密密钥,从而导致系统效率低下。尽管已经提出了多权限访问控制方案,但是由于每个权限仍然独立地管理不相交的属性集,因此这些方案仍不能克服单点瓶颈和低效率的缺点。在本文中,我们提出了一种新颖的异构框架,以消除单点性能瓶颈的问题,并提供一种具有审计机制的更有效的访问控制方案。我们的框架使用多个属性授权机构来分担用户合法性验证的负担。同时,在我们的方案中,引入了一个中央机构来为经合法性验证的用户生成密钥。与其他多权限访问控制方案不同,我们方案中的每个权限都单独管理整个属性集。为了增强安全性,我们还提出了一种审核机制,以检测哪个属性授权错误地或恶意地执行了合法性验证过程。分析表明,我们的系统不仅可以保证安全性要求,而且在密钥生成方面也有很大的改进。

著录项

  • 来源
  • 作者单位

    Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China;

    Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China;

    Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China;

    Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China;

    Department of Computer Science, San Francisco State University, San Francisco, CA, USA;

    Computer and Information Science Department, Fordham University, New York City, NY, USA;

    Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Access control; Cloud computing; Robustness; Electronic mail; Encryption;

    机译:访问控制;云计算;稳健性;电子邮件;加密;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号