节点文献

多用户公钥可搜索加密中访问控制的研究

Research on Access Control of Searchable Encryption in Multi-User Setting

【作者】 李磊

【导师】 许春根;

【作者基本信息】 南京理工大学 , 应用数学, 2019, 硕士

【摘要】 在以大数据,人工智能等为代表的高新技术快速发展的当今社会,信息安全已越来越受到人们的重视。其中密码学对数据的保护起到了举足轻重的作用,而信息技术也对密码学的发展和应用提供了广阔的背景和支持。本文研究公钥可搜索加密,主要为优化多用户共享云端资源情境下的访问控制和密钥管理。首先,在多用户场景下,为了保护用户之间的信息交流,我们根据经典的Diffie-Hellman密钥协商思想,利用双线性映射构造了一个基于身份的可认证的两方密钥协商协议,通过执行本协议得到的共享密钥将用来保护用户之间的会话。作为可搜索加密系统的辅助工具,此协议算法能够抵御未知密钥共享攻击,提高系统的安全性。在核心内容的研究上,针对目前可搜索加密访问控制不够细粒度和缺乏灵活性,本文提出的第一个方案对数据内容进行分类,并根据类别授权用户的访问。服务器利用关键字和用户公钥构造一个访问控制矩阵,后续结合此权限矩阵和用户的搜索陷门便能够判断某次搜索请求是否合法。因而本方案能够在实现访问控制的基础上缩小搜索范围,提高系统的检索效率。由于用户自行保管密钥,本方案无需管理密钥的可信中心。为了满足用户对资源的搜索,一般需要生成与用户数量对应的密文个数。针对此类造成的资源浪费,我们提出的第二个方案以基于身份的加密体制为基础,设定不同层级用户的密钥长度不同,实现密钥生成和身份的对应关系,满足每一层的用户都能生成本层以下用户的搜索密钥。通过该机制使得本方案既能实现访问权限的分层垂直管理,又能同时减少密文的数量,节省资源。

【Abstract】 With the rapid development of information technology such as big data and artificial intelligence,people now are paying more attention to information security.As one represent of information security technology,cryptography has been playing a very important role in protecting data.At the same time,information technology provides a broad background and support for the development and application of cryptography.In this paper,we study the public key searchable encryption and mainly focus on access control and key management in the multi-user setting.First,to protect sessions from eavesdropping,based on the classic Diffie-Hellman key agreement protocol,this paper constructs a two-party authenticated key agreement protocol with the use of bilinear mapping.The shared key will be used to protect sessions between users.As an auxiliary tool of searchable encryption system,this protocol algorithm can resist unknown key sharing attacks and improve the security of the system.As to main contents,to achieve more fine-grained and flexible access control mechanism,in the first scheme,the manager classifies his data and authorizes users according to categories.The cloud server in this scheme builds an access control matrix,which will be used to verify whether a trapdoor is valid or not.By this way can we achieve access control and narrow search range at the same time.Also we do not need a trusted center to do the key management.In the multi-user setting of public key searchable encryption,it is generally necessary to generate indexes as many as the number of users,which is a waste of resource.This paper constructs another searchable encryption based on identity,whose users on different levels should have different keys in length.In other words,a user’s identity and secret key relates to his rights to search.Every user is able to search data encrypted by others whose level is lower than his.By this way can achieve vertical management of access control.

节点文献中: