云计算中一种紧凑型的外包访问控制方案

A compact and Outsourced Access Control Scheme in Cloud Computing

  • 摘要: 密文策略的属性加密是实现云平台上安全的访问控制方案的最佳选择。然而,在大多数密文策略的属性加密方案中,用户密钥长度与属性的个数之间成线性关系;用户的解密时间与访问结构的复杂度成正比关系。为了减少用户密钥的存储和解密计算开销,本文提出一种面向云计算平台的紧凑型的外包访问控制方案。方案中的访问结构可以支持“与”、“或”以及“门限”三种策略。它仅采用简单的哈希和异或运算就可以验证用户外包解密返回的数据是否正确。在随机预言机模型中,基于aMSE-DDH难题,证明了方案是选择密文攻击安全的。分析表明,本文方案能够安全的实现云计算环境下的访问控制,尤其当用户终端设备受限时实现的访问控制。

     

    Abstract: Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is a promising encryption technology for secure access control in cloud computing. However, in most of the existing CP-ABE schemes, the size of decryption key linearly increases with the number of attributes, and the decryption time follows a linear relationship with the complexity of access structure increasing. To reduce the storage cost of user’s key and the time cost of decryption, in this paper, a compact and outsourced access control scheme is provided in cloud computing. In the proposed scheme, access structure associated with ciphertext can support three policies: AND, OR, and Threshold. At the same time, it can verify the result of outsourcing decryption only using some hash computations and XOR operations. Based on the aMSE - DDH problem, the proposed scheme is proved to be selectively secure against chosen-ciphertext attack in the random oracle model. In addition, the analyses show that it is efficient to securely achieve access control in cloud computing, especially when the terminal devices associated with user are constrained.

     

/

返回文章
返回