摘要
目前云数据安全存储方案中,数据拥有者加密数据上传到云中,但却不能很好地支持加密数据分享,尤其是分享给多个用户时,可扩展性不强。针对这个问题提出一种基于身份的代理重加密方案,该方案不需要云完全可信但却又能灵活地进行数据安全共享。在具体构造上,结合基于身份的加密,用一个强不可伪造的一次签名方案使被转换后的密文具有公开验证性,且能达到被转换后的密文在标准模型下具有选择密文安全性。由于该类方案无须使用公钥证书、能支持细粒度的访问控制且可扩展性较好,因此可以较好地适用于安全云数据共享。
Currently most of the solutions of cloud data security storage required the data owner encrypted his data before out- sourcing the data to the cloud, but this method couldn't support flexible data sharing, especially for the multi-user setting. Aimed at solving this problem, this paper proposed a new identity based proxy re-encryption scheme, which didn't need the cloud to be completely trusted, but could also be used to share the data safely. In the concrete construction, this paper used a strongly non-forgeable signature scheme to let the encrypted ciphertexts be publicly verifiable, this scheme could also be cho- sen ciphertext secure in the standard model. For the proposed scheme can be used without certificate, support fine-grained ac- cess control and be very scalable, thus it can be used for secure data sharing in the cloud.
出处
《计算机应用研究》
CSCD
北大核心
2016年第11期3450-3454,共5页
Application Research of Computers
基金
国家自然科学基金资助项目(61379152)
陕西省自然科学基金资助项目(2014JM8300)
关键词
云存储安全
数据共享
代理重加密
标准模型
可公开验证
cloud storage secure
data sharing
proxy re-encryption
standard model
publicly verifiable