节点文献
面向云数据共享的高效属性基加密技术研究
Efficient Attribute-Based Encryption for Cloud Data Sharing
【作者】 李想;
【导师】 田晖;
【作者基本信息】 华侨大学 , 软件工程, 2021, 硕士
【摘要】 随着云计算技术的快速发展,用户个人及企业将大量的数据存储在云中。因此,通过云数据共享,各服务提供商可使用数据挖掘和分析等技术为云用户提供优质的服务。尽管云数据共享有许多优点,但仍然面临许多安全问题。其中一个重点问题就是,如何保护云中数据的机密性。属性基加密技术实现了一对多的数据加密和细粒度的访问控制,已经被广泛地应用于学术界和工业界中。但考虑用户特性以及复杂的实际场景,属性基加密技术仍面临诸多安全和性能上的挑战,如隐私泄漏、实体不可信及实时加解密需求等。为解决上述云数据共享中存在的问题,本文提出了相应的高效属性基加密方案,具体研究工作如下:(1)针对用户隐私易暴露的问题,提出了支持全隐私保护的轻量属性基加密方案,它可以在三个关键阶段(即密钥生成,访问控制策略设置和外包解密)实现完全隐私保护,同时减少了用户端的计算开销。具体来说,为了保护密钥生成过程中的隐私,本方案设计了用户和属性机构之间的轻量级两方安全计算协议来生成密钥。为了在访问控制策略设置期间保护隐私,本方案提出了有效的策略隐藏机制,该机制仅显示属性名称并有效地隐藏属性值。为了保护外包解密期间的用户隐私,本方案提出了混合身份验证方法,该方法不需要将属性值提交到云。此外,为了实现物联网设备的轻量级计算,本方案采用了在线/离线加密和外包解密技术。最后,正式的安全证明表明本方案是安全的。渐进复杂度分析和实验结果表明,所提出的方案具有比最新方案更高的计算效率。(2)针对实体非完全可信的问题,提出了基于联盟链的可信属性基加密方案。首先,针对云服务商和属性机构的不可信问题,本方案引入了基于云服务商和属性机构的联盟链,并设计了基于链码的实体监督机制,以防止实体之间的合谋。其次,针对用户的不可信问题,本方案给出了支持隐藏用户的公开可追踪方法和基于索引用户表的恶意用户撤销方法。具体来说,公开可追踪方法将用户的属性私钥与全局虚拟身份相绑定,以实现隐藏恶意用户的追踪。此外,我们还设计了索引用户表,辅助实现高效的代理密钥更新,从而能够撤销特定的恶意用户。最后,严格的安全性证明和性能分析验证了所提出方案的安全性和有效性。(3)针对自动驾驶场景下的数据共享问题,提出了基于雾计算的属性基加密方案,为实时的路况分析及后续的分析利用奠定了基础。本方案提出了在线/离线的混合签密方法,可实现确保数据机密性和完整性的同时,减轻自动驾驶车辆的签名和加密负担。为了提高雾节点的验证效率,本方案提出了基于身份的聚合认证方法,使雾节点能够批量认证密文的完整性。此外,雾节点传送消息给自动驾驶车辆时,本方案使用了基于身份的短签名方法,能够在保证雾节点消息的可靠性同时,减轻自动驾驶车辆的验证负担。最后,对提出方案的安全性给出了严格的证明和分析,并对其性能进行了分析和评估。结果表明,该方案可利用雾计算节点极大降低用户端的计算开销。
【Abstract】 With the rapid development of cloud computing technology,the data of users and enterprises are stored in the cloud.Through cloud data sharing,various service providers can provide high-quality services to cloud users by using data mining and analysis technologies.Although cloud data sharing has many advantages,it still faces many security problems.How to ensure the security of data stored in the cloud has become one of the biggest challenges at present.As a promising solution for realizing fine-grained access control,Attribute-Based Encryption(ABE)can be used to ensure data security.However,ABE technology still faces some new security challenges,considering the characteristics of users and complex real scenes.This dissertation mainly focuses on the research of efficient ABE technology for cloud data sharing and proposes corresponding schemes.The details of this dissertation are as follows:(1)For risk of privacy exposure for multiple users,a lightweight ABE scheme with full privacy protection is proposed,which can achieve full privacy protection in the three key stages(i.e.,key generation,access control,and outsourced decryption),while reducing consumption overhead on the user side.Specifically,to protect privacy during key generation,a lightweight two-party secure computing protocol between the user and the authority is designed to generate secret keys;to protect privacy during the access control policy setting,we present an efficient policy hidden strategy,which only reveals attribute names and efficiently hides attribute values;to protect privacy during outsourced decryption,we propose a hybrid authentication method that does not need to submit attribute values to the cloud.Moreover,to achieve lightweight computation for Io T devices,online/offline encryption and outsourced decryption technologies are employed.Finally,formal security proofs show that our scheme is secure.The asymptotic complexity analyses and experimental results demonstrate that the presented scheme achieves higher computation efficiency than the state-of-the-art ones.(2)To solve the problem of incomplete trust of entities,a trusted ABE scheme based on federated blockchain is proposed.Firstly,aiming at the untrustworthiness problem of cloud service providers and attribute authorities,a federated blockchain based on cloud service providers and attribute authorities is introduced in this scheme.Using the entity supervision mechanism based on chaincode can prevent collusion among entities.Secondly,aiming at the untrustworthiness problem of users,this scheme gives a public tracking method to support hidden users and a malicious user revocation method based on index user list.Specifically,the publicly traceable method binds the user’s attribute private key to the global virtual identity,so as to trace the hidden malicious users.The public revocable method firstly presents the indexed user list for efficient proxy key updates.Finally,the security and effectiveness of the proposed scheme are verified by strict security proof and performance analysis.(3)For autonomous driving scenarios,an edge-assisted ABE scheme for autonomous driving is proposed.This scheme proposes a hybrid online/offline signcryption method,which can guarantee data confidentiality and integrity while reducing the signcryption burden of autonomous vehicles.To improve the authentication efficiency of the fog nodes,an identity-based aggregated authentication method is proposed,which enables fog nodes to batch authenticate the integrity of the ciphertext.When fog nodes send messages to autonomous vehicles,the identity-based short signature method is adopted,which can ensure the reliability of fog node messages and reduce the verification burden of autonomous vehicles.Finally,the security analysis,theoretical analysis and experimental evaluation are carried out.The results show that using fog nodes in this scheme can reduce the amount of computation on the user side.
【Key words】 Attribute-based encryption; Cloud computing; Data confidentiality; Privacy protection; Fog computing;
- 【网络出版投稿人】 华侨大学 【网络出版年期】2024年 09期
- 【分类号】TP309