期刊文献+

A Practical Group Key Management Algorithm for Cloud Data Sharing with Dynamic Group

A Practical Group Key Management Algorithm for Cloud Data Sharing with Dynamic Group
下载PDF
导出
摘要 Cloud data sharing service, which allows a group of people to work together to access and modify the shared data, is one of the most popular and efficient working styles in the enterprises. However, the cloud server is not completely trusted, and its security could be compromised by monetary reasons or caused by hacking and hardware errors. Therefore, despite of having advantages of scalability and flexibility, cloud storage service comes with privacy and the security concerns. A straightforward method to protect the user's privacy is to encrypt the data stored at the cloud. To enable the authenticated users to access the encrypted cloud data, a practical group key management algorithm for the cloud data sharing application is highly desired. The existing group key management mechanisms presume that the server is trusted. But, the cloud data service mode does not always meet this condition. How to manage the group keys to support the scenario of the cloud storage with a semi-trusted cloud server is still a challenging task. Moreover, the cloud storage system is a large-scale and open application, in which the user group is dynamic. To address this problem, we propose a practical group key management algorithm based on a proxy re-encryption mechanism in this paper. We use the cloud server to act as a proxy tore-encrypt the group key to allow authorized users to decrypt and get the group key by their private key. To achieve the hierarchical access control policy, our scheme enables the cloud server to convert the encrypted group key of the lower group to the upper group. The numerical analysis and experimental results further validate the high efficiency and security of the proposed scheme. Cloud data sharing service, which allows a group of people to work together to access and modify the shared data, is one of the most popular and efficient working styles in the enterprises. However, the cloud server is not completely trusted, and its security could be compromised by monetary reasons or caused by hacking and hardware errors. Therefore, despite of having advantages of scalability and flexibility, cloud storage service comes with privacy and the security concerns. A straightforward method to protect the user's privacy is to encrypt the data stored at the cloud. To enable the authenticated users to access the encrypted cloud data, a practical group key management algorithm for the cloud data sharing application is highly desired. The existing group key management mechanisms presume that the server is trusted. But, the cloud data service mode does not always meet this condition. How to manage the group keys to support the scenario of the cloud storage with a semi-trusted cloud server is still a challenging task. Moreover, the cloud storage system is a large-scale and open application, in which the user group is dynamic. To address this problem, we propose a practical group key management algorithm based on a proxy re-encryption mechanism in this paper. We use the cloud server to act as a proxy tore-encrypt the group key to allow authorized users to decrypt and get the group key by their private key. To achieve the hierarchical access control policy, our scheme enables the cloud server to convert the encrypted group key of the lower group to the upper group. The numerical analysis and experimental results further validate the high efficiency and security of the proposed scheme.
出处 《China Communications》 SCIE CSCD 2016年第6期205-216,共12页 中国通信(英文版)
基金 partially supported by National Natural Science Foundation of China No.61202034,61232002,61303026,6157237861402339 CCF Opening Project of Chinese Information Processing No.CCF2014-01-02 the Program for Innovative Research Team of Wuhan No.2014070504020237 Fundamental Application Research Plan of Suzhou City No.SYG201312 Natural Science Foundation of Wuhan University No.2042016gf0020
关键词 proxy re-encryption group key management bilinear map encrypted cloud storage 管理算法 数据共享 组密钥 加密机制 群组 存储服务 用户隐私 访问控制策略
  • 相关文献

参考文献4

二级参考文献45

  • 1Blaze M. A cryptographic file system for UNIX//Proceedings of the 1st ACM Conference on Communications and Computing Security. Fairfax, Virginia, USA, 1993: 9-16 被引量:1
  • 2Fu K. Group sharing and random access in cryptographic storage file system [Master dissertation]. Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, USA, 1999 被引量:1
  • 3Goh E, Shacham H, Modadugu N, Boneh D. SiRiUS: Securing remote entrusted storage//Proceedings of the 10th Network and Distributed Systems Security Symposium (NDSS'03). San Diego, California, USA, 2003: 131-145 被引量:1
  • 4Halcrow M A. eCryptfs: An enterprise-class cryptographic file system for Linux//Proceedings of the 2005 Linux Symposium. Ottawa, Canada, 2005:201-218 被引量:1
  • 5Hughes J P, Feist C J. Architecture of the secure file system//Proceedings of the 8th IEEE Symposium on Mass Storage Systems. San Diego, USA, 2001:277-290 被引量:1
  • 6Kallahalla M, Riedel E, Swaminathan R, Wang Q, Fu K. Plutus: Scalable secure file sharing on entrusted storage// Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST' 03). San Francisco, CA, USA, 2003:29-42 被引量:1
  • 7Wright C P, Martino M C, Zadok E. Ncryptfs: A secure and convenient eryptographie file system//Proceedings of the USENIX Annual Technical Conference. San Antonio, Texas, USA, 2003:197-210 被引量:1
  • 8Merkle R C. A digital signature based on a conventional encryption function//Proceedings of Advanced in Cryptology- CRYPTO'87. LNCS293. Springer Verlag, 1988:369-378 被引量:1
  • 9Neumann B C, Ts'o T, Kerberos: An authentication service for computer networks, IEEE Communications, 1994, 32 (9) : 33-38 被引量:1
  • 10Zhu Y, Hu Y. SNARE: A strong security scheme for network-attached storage//Proceedings of the 22nd International Symposium on Reliable Distributed Systems (SRDS' 03). Florence, Italy, 2003:250-259 被引量:1

共引文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部