节点文献
数据安全视角下数据分享方案的研究
Research on Data Sharing Scheme in the Perspective of Data Security
【摘要】 针对云文件数据在使用期后不及时删除易导致非授权访问及隐私数据泄露等问题,结合DHT(分布式哈希表)网络实时更新的特性,提出了一种AES与国密SM2混合加密的云文件数据安全自毁方案。首先数据所有端用AES对称加密算法加密待上传文件得到文件密文,然后对文件密文随机抽样,再将密文索引与AES密钥封装成封装体(PAC),其次将PAC用私钥进行国密SM2非对称加密成封装体密文(EP),最后将EP传至DHT网络,并将不完整密文与抽样密文上传至云端。数据使用端下载使用数据的操作是上传操作的逆操作。数据生命到期时可通过DHT网络自主更新实现定期删除EP,密文的覆写删除是通过调用HDFS的接口上传随机数据实现。通过密钥和云端密文的删除实现云数据的安全自毁。实验结果表明方案的整体性能表现良好。
【Abstract】 In view of the problems such as unauthorized access and privacy data leakage caused by not timely deletion of cloud data after the use period, a security self-destruction scheme of cloud data encrypted by AES and SM2 was proposed in combining with the real-time update feature of DHT(distributed hash table) network. Firstly, AES symmetric encryption algorithm was used to encrypt the file to be uploaded to obtain the file ciphertext at the data owner side, then the file ciphertext was randomly sampled, and then the ciphertext index and AES key were encapsulated into a package(PAC). Secondly, the PAC was encrypted asymmetrically with the private key SM2 into an encrypted package(EP). Finally, the EP was sent to the DHT network, and incomplete ciphertext and sampled ciphertext were uploaded to the cloud. The operation of downloading the used data at the data-using side was the inverse operation of the uploading operation. When the data life expired, the EP could be deleted periodically through the autonomous update of DHT network, and ciphertext overwrite deletion was implemented by calling the interface of HDFS to upload random data. The security self-destruction of cloud data was realized by the deletion of keys and cloud ciphertexts. The experimental results show that the overall performance of the scheme is good.
【Key words】 Mixed encryption; Security sharing; Ciphertext sampling; Privacy protection; SM2 algorithm;
- 【文献出处】 西南科技大学学报 ,Journal of Southwest University of Science and Technology , 编辑部邮箱 ,2023年01期
- 【分类号】TP309.2
- 【下载频次】111