节点文献

云存储中支持多关键字搜索的盲存储算法研究

The Research on Blind Storage Algorithm Supporting Mulit-Keywords Search in Cloud Storage

【作者】 张超

【导师】 李谢华; 王守选;

【作者基本信息】 湖南大学 , 计算机技术(专业学位), 2018, 硕士

【摘要】 随着云存储技术的高速发展,由于其管理灵活、价格低、数据访问便捷的特点受到了许多用户的青睐。然而近年来,云端数据泄露的事件不断地在一些大型云服务供应商(Cloud Service Provider,CSP)发生,使得用户开始重视云端数据的安全性问题。为保障云端数据的安全性,通常对数据进行先加密后存储的方式。然而,这种方式在加密数据的存储安全和检索效率方面都有一定的局限性。因此,如何提高云数据存储的安全性,以及如何提高加密云数据的检索效率是当前云安全领域研究的重点问题。针对此,本文将在密文的高效搜索和授权搜索这两个方面进行深入研究,论文的研究内容主要包括以下两个方面:首先,针对传统盲存储算法在云存储环境中目前主要存在的查询和存储效率低的问题,本文提出了一种基于计数型布鲁姆过滤器的盲存储算法(CBF-BS)。CBF-BS通过将数据分割、加密、混淆后存储于服务器端。与传统BS算法相比,本文提出的算法将真实的文档分块之间互相混淆,不仅保证了云端数据的安全性,还避免了传统BS算法利用无效的数据块作为混淆块而导致存储空间浪费的问题。此外,CBF-BS算法利用CBF为存储数据建立索引,其查询复杂度仅与哈希函数的个数有关。传统BS算法利用伪随机算法为存储数据建立索引,其查询复杂度与文档数相关。而在保证系统允许的最大误判率的前提下,CBF所采用的哈希函数的个数远少于存储的文档数,因此,CBF-BS可有效地提高查询效率。最后,理论分析和仿真实验表明,CBF-BS的存储及查询效率有明显的提升。其次,在深入研究了目前主流的授权搜索方案后,发现其中绝大部分方案还是依赖授权中心来进行访问控制策略的制定,且不支持搜索结果的排序。鉴于此,本文提出了支持结果排序的可授权密文检索方案(ARSS),该方案在盲存储算法的基础上用多个授权机构来替换授权中心进行权限认证,不仅避免了单个授权中心可能遭受攻击而造成重要数据泄露的风险,并且多个授权机构联合进行权限认证,可以有效提高认证效率。此外,方案引入了文档相似度权值的概念,并利用权值作为搜索结果的排名依据,如此一来,用户可以获取更精确的搜索结果,以此来增强用户的搜索体验。最后,理论分析和仿真结果均验证了方案的有效性。

【Abstract】 With the rapid development of cloud storage technology,it is favored by many users because of its flexible management,low price,and convenient data access.However,in recent years,incidents of cloud data leakage continue to occur in some large cloud service providers(CSPs),making users begin to pay attention to cloud data security issues.To ensure the security of data in the cloud,data is usually encrypted and then stored.However,this method has certain limitations in the storage security and retrieval efficiency of encrypted data.Therefore,how to improve the security of cloud data storage and how to improve the retrieval efficiency of encrypted cloud data are the key issues in the current cloud security research.In view of this,this article will conduct in-depth research on the two aspects of efficient search and authorized search of ciphertext.The research content of the paper mainly includes the following two aspects:First of all,aiming at the problem of low query and storage efficiency in traditional cloud storage algorithms in cloud storage environment,this paper proposes a blind storage algorithm based on counting Bloom filter(CBF-BS).CBF-BS stores data on the server by splitting,encrypting,and obfuscating the data.Compared with the traditional BS algorithm,the proposed algorithm confuses the actual document blocks,not only ensures the security of the cloud data,but also avoids the traditional BS algorithm to use invalid data blocks as an obfuscated block,resulting in wasted storage space.The problem.In addition,the CBF-BS algorithm uses CBF to index the stored data.The query complexity is only related to the number of hash functions.The traditional BS algorithm uses a pseudo-random algorithm to index the stored data.Its query complexity is related to the number of documents.On the premise of ensuring the maximum misjudgment rate allowed by the system,the number of hash functions used by CBF is far less than the number of stored documents.Therefore,CBF-BS can effectively improve the query efficiency.Finally,theoretical analysis and simulation experiments show that the storage and query efficiency of CBF-BS has improved significantly.Secondly,after deeply researching the current mainstream authorizing search scheme,it is found that most of the programs rely on the authorization center to formulate the access control strategy and do not support the sorting of search results.In view of this,this paper proposes an Authorized Ciphertext Retrieval Scheme that supports the ordering of results(ARSS).This scheme replaces Authorization Centers with multiple Authorities to perform rights authentication on the basis of Blind Storage Algorithms,not only avoiding the possibility that a single Authorization Center may suffer.Attacks cause the risk of important data leakage,and multiple authorized organizations jointly perform privilege authentication,which can effectively improve the efficiency of authentication.In addition,the scheme introduces the concept of document similarity weights and uses the weights as the ranking of search results.In this way,users can obtain more accurate search results to enhance the user’s search experience.Finally,theoretical analysis and simulation results verify the effectiveness of the scheme.

  • 【网络出版投稿人】 湖南大学
  • 【网络出版年期】2019年 01期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络