论文标题
基于角色的加密方案,用于在多组织中保护外包云数据
A Role-Based Encryption Scheme for Securing Outsourced Cloud Data in a Multi-Organization Context
论文作者
论文摘要
基于角色的访问控制(RBAC)是一个流行的模型,它映射角色以访问资源的权限,然后向用户发挥作用以提供访问控制。基于角色的加密(RBE)是RBAC模型的一种加密形式,将传统的RBAC与加密加密方法集成在一起,其中RBAC访问策略嵌入了加密数据本身中,以便任何扮演合格角色角色的用户都可以通过解密来访问数据。但是,现有的RBE方案一直集中在单一组织云存储系统上,同一组织的用户可以访问存储的数据。本文介绍了一种新颖的RBE方案,对多组织云存储系统有效撤销了有效的用户撤销,其中存储了来自多个独立组织的数据,并且可以由任何其他组织的授权用户访问。此外,还引入了外包解密机制,使用户能够将昂贵的加密操作委派给云,从而减少最终用户的开销。对拟议方案的安全性和绩效分析表明,它可以证明它可以抵抗所选的明文攻击,并且由于其低计算开销而对实际应用有用。
Role-Based Access Control (RBAC) is a popular model which maps roles to access permissions for resources and then roles to the users to provide access control. Role-Based Encryption (RBE) is a cryptographic form of RBAC model that integrates traditional RBAC with the cryptographic encryption method, where RBAC access policies are embedded in encrypted data itself so that any user holding a qualified role can access the data by decrypting it. However, the existing RBE schemes have been focusing on the single-organization cloud storage system, where the stored data can be accessed by users of the same organization. This paper presents a novel RBE scheme with efficient user revocation for the multi-organization cloud storage system, where the data from multiple independent organizations are stored and can be accessed by the authorized users from any other organization. Additionally, an outsourced decryption mechanism is introduced which enables the users to delegate expensive cryptographic operations to the cloud, thereby reducing the overhead on the end-users. Security and performance analyses of the proposed scheme demonstrate that it is provably secure against Chosen Plaintext Attack and can be useful for practical applications due to its low computation overhead.