节点文献

面向多方的属性基可搜索加密方案研究

Research on Multi-party Attribute-Based Searchable Encryption Scheme

【作者】 李文静

【导师】 刘雪艳;

【作者基本信息】 西北师范大学 , 计算机科学与技术, 2025, 硕士

【摘要】 随着物联网技术的快速发展,数据规模呈指数级增长,信息泄露事件频发,使数据安全与隐私保护面临严峻挑战。在云计算环境下,多数据所有者对协同管理、文件共享的需求不断增加,然而,现有属性基可搜索加密方案在搜索效率、数据所有权管理、密钥管理、用户权限控制及策略隐藏更新等方面仍存在诸多局限,难以满足复杂应用场景的安全与性能需求。为解决上述问题,本文在雾计算环境下结合可搜索加密、多权威管理和恶意用户追踪等技术,提出三个属性基可搜索加密方案:(1)针对物联网环境下数据安全与搜索灵活性不足的问题,提出一种面向多权威的属性基动态关键字搜索加密方案。首先,采用分布式权威架构,将属性集划分为互不相交子集并由独立属性权威管理,有效消除单点性能瓶颈并提升系统鲁棒性。其次,通过构建动态关键字匹配算法,允许关键字集与查询集存在部分匹配即返回结果,显著提高搜索效率。最后,引入雾计算节点实现了请求预处理与部分解密,降低用户端延迟。(2)针对多数据所有者环境下的密钥泄露与权限管理难题,提出一个可追踪可撤销的多数据所有者属性基可搜索加密方案。首先,采用权威中心与属性权威分离式密钥生成机制,其中权威中心绑定用户身份生成身份密钥,属性权威基于属性生成访问密钥,实现细粒度访问控制与密钥溯源。其次,通过线性秘密共享实现多数据所有者联合加密,数据用户需获得多个数据所有者授权才能解密数据,从而提升数据共享的安全性。最后,结合身份绑定机制与二叉树结构存储用户身份信息,实现恶意用户追踪与撤销,并动态更新撤销列表,以保障系统的长期安全性。(3)针对策略暴露风险与策略更新效率难题,提出一个支持策略隐藏更新的多方属性基可搜索加密方案。首先,通过随机化、填充虚假属性及加密索引信息,实现访问策略的隐藏,使得雾节点仅能存储混淆后的索引值,而无法解析具体的访问策略,从而增强系统的隐私保护能力。其次,设计高效的策略更新机制,结合访问结构的灵活重构与密钥更新技术,使数据所有者能够在无需重新加密数据的情况下动态调整访问策略。最后,借助雾计算架构,将部分策略隐藏和更新计算转移至雾节点,减少用户端的计算开销,从而提升系统的运行效率与安全性。

【Abstract】 With the rapid development of the Internet of Things technology,the scale of data has grown exponentially,and information leakage incidents have occurred frequently,making data security and privacy protection face severe challenges.In the cloud computing environment,the demand of multi-data owners for collaborative management and file sharing is increasing.However,the existing attribute-based searchable encryption schemes still have many limitations in search efficiency,data ownership management,key management,user rights control and policy hidden update,which are difficult to meet the security and performance requirements of complex application scenarios.In order to solve the above problems,this thesis proposes three attribute-based searchable encryption schemes by combining searchable encryption,multi-authority management and malicious user tracking in fog computing environment:(1)Aiming at the problem of insufficient data security and search flexibility in the Internet of Things environment,a multi-authority oriented attribute-based dynamic keyword search encryption scheme is proposed.Firstly,the distributed authority architecture is adopted to divide the attribute set into disjoint subsets and managed by independent attribute authority,which effectively eliminates the single-point performance bottleneck and improves the system robustness.Secondly,by constructing a dynamic keyword matching algorithm,it allows partial matching between the keyword set and the query set,that is,returns the result,which significantly improves the search efficiency.Finally,the fog computing node is introduced to realize request preprocessing and partial decryption,which reduces the cloud computing load and client delay.(2)A traceable and revocable multi-data owner attribute-based searchable encryption scheme is proposed to solve the problem of key leakage and privilege management in multi-data owner environment.Firstly,the separation key generation mechanism in the charge of authority center and attribute authority is adopted,the authority center binds the user identity to generate the identity key,and the attribute authority generates the access key based on the attribute,so as to realize fine-grained access control and key traceability.Secondly,multi-data owner joint encryption is realized through linear secret sharing,and data users need to obtain multiple data owner authorizations to decrypt data,thereby improving the security of data sharing.Finally,the identity binding mechanism and the binary tree structure are combined to store the user identity information,malicious user tracking and revocation are realized,and the revocation list can be dynamically updated to ensure the long-term security of the system.(3)Aiming at the problem of policy exposure risk and policy update efficiency,a multi-attribute-based searchable encryption scheme supporting policy hiding and updating is proposed.Firstly,by randomizing,filling pseudo attributes and encrypting index information,the access policy is hidden,so that the fog node can only store the confused index value,but can not parse the specific access policy,thus enhancing the privacy protection ability of the system.Secondly,an efficient policy update mechanism is designed,which combines the flexible reconstruction of access structure and key updating technology,so that the data owner can dynamically adjust the access policy without re-encrypting the data.Finally,with the help of the fog computing architecture,some policy hiding and updating calculations are transferred to the fog nodes to reduce the computing overhead of the client,thereby improving the operating efficiency and security of the system.

  • 【分类号】TP309.7
节点文献中: 

本文链接的文献网络图示:

本文的引文网络