节点文献

云环境下基于身份的数据完整性证明的研究及应用

Research And Application of Identity-Based Provable Data Possession in Clouds

【作者】 陈阳

【导师】 赵洋;

【作者基本信息】 电子科技大学 , 软件工程(专业学位), 2016, 硕士

【摘要】 随着用户数据量的爆发式增长与云计算技术的不断发展,越来越多的用户开始选择将自己的数据外包以减轻存储压力。云存储服务由于其按需付费、高扩展性与可随时随地访问等优点成为众多用户的选择。但是用户对存储在云服务器上数据安全性的担忧又成为阻碍云存储的进一步发展的重要因素。因此如何向用户证明其存储在云服务器上的数据是完整的就成为一个亟待解决的关键问题。本文以云环境下的数据完整性证明作为研究内容,旨在以用户需求为导向在前人研究的基础上提出可满足用户需求,同时又可降低用户负担、保护用户隐私的高适用性远程数据完整性证明方案。本文主要工作如下:1.本文首先给出了云环境下数据完整性证明的研究意义并综述了其研究现状。然后介绍了云存储与数据完整性证明的相关基础知识,并详细介绍了远程数据完整性证明的经典模型及以此模型为基础进行方案设计的方法、安全要求与主要性能参数。2.本文考虑到现有方案的不足与用户需求,设计了一种基于身份的授权数据完整性证明方案。方案的设计基于双线性对技术,通过引入基于身份加密体制减轻用户公钥证书管理负担。同时,方案只允许拥有用户授权的第三方代理用户完成完整性检查。另外,方案还加入了数据块-标签对检验以实现用户与云服务商间的公平责任。文中给出了方案的实现过程及安全和性能分析。3.考虑到授权数据完整性证明方案难以撤销已有授权的问题,本文给出了一种可撤销授权的新方案。新方案仍以双线性对与基于身份加密体制为基础,通过引入分离授权的思想实现低成本的授权验证与授权撤销。文中同样给出了方案的具体设计与安全和性能分析。4.本文最后以Hadoop为例简要介绍了分布式文件系统与MapReduce的概念,给出了Hadoop云存储平台的基本操作方法,并通过模拟实验详细分析了文中两个方案的计算开销、额外存储开销与通信开销等。

【Abstract】 With the explosive growth of data volume and the continuous development of cloud computing technology, more and more users are choosing to outsource their data storage to relieve pressure. Since cloud storage is pay-on-demand, highly extensible and accessible, it has become the preferred way of outsourcing their data. However, users’ concern about the security of their remote data has become the resistance of further development of cloud storage service. Therefore, how to prove the remote data is unmodified has become a core problem in cloud storage.In this thesis, we study provable remote data possession. Based on the predecessors’ research, we design new schemes which not only can meet users’ requirements, but also can reduce their burden and protect privacy. The main work is as follows:1. This thesis presents the research meaning of provable remote data possession and reviews the research status. Then, we introduce the basic knowledge of cloud storage and provable data possession. At last, we give the detail on the classic model of provable data possession including design method, safety requirements and main performance parameters.2. In this thesis, considering users’ requirements and the shortcomings of existing schemes, we design an identity-based authorized third party provable data possession in clouds. The new cheme is based on bilinear pairings and uses identity-based encryption technology to reduce the burden of certificate management. At the same time, the scheme only allowes the third party who has user’s authorization to complete data aduit process. In addition, data block-tag pair check is introduced to achieve fair responsibility for both sides. We give the concrete procedures,security analysis and performance analysis.3. Considering the authorized provable data possession scheme is difficult to revoke the existing authorization, this thesis proposes an identity-based revocable authorization provable data possession scheme. It is still based on bilinear pairings and identity-based encryption. But by introducing the idea of separated authorization, the scheme can revoke the third part’s authorization with a low cost. We also give the scheme design, security analysis and performance analysis.4. This thesis introduces the concept of Hadoop Distributed File System and MapReduce, and gives basic operation methods of Hadoop cloud storage platform. Through simulation experiments,we analyse the computational overhead, additional storage costs and communication overhead of the two schemes in detail.

  • 【分类号】TP333;TP309
  • 【被引频次】2
  • 【下载频次】145
  • 攻读期成果
节点文献中: 

本文链接的文献网络图示:

本文的引文网络