Research on cloud access control technology based on consortium blockchains
-
摘要:
针对云存储环境中单授权中心的安全性问题,提出一种以CP-ABE模型为基础,同时基于联盟区块链的可撤销多授权机构访问控制模型(Revocable Multi-Authority Access Control Based on Consortium Blockchain, RMACB).该模型以树形结构描述属性授权中心(Attribute Authority, AA),同时利用可信证书链(Trusted Certificate Chain, TCC)和成员服务提供商(Membership Service Provider, MSP)对联盟链上的节点进行身份管理和权限控制.将用户密钥嵌入到密文中去,实现可撤销的云访问控制技术,由云服务提供商来执行重加密过程,减轻了数据所有者的加密负担.实验验证了提出方案具有更低的计算成本和较高的安全性.
Abstract:Aiming at the security problem of single authorization center in cloud storage environment, a revocable multi-authority access control based on CP-ABE model and federated block chain is proposed. Attribute Authority (AA) is described in a tree structure.At the same time, the Trusted Certificate Chain (TCC) and Membership Service Provider (MSP) are used to manage the identity and control the permissions of the nodes in the Chain. By embedding the user key into the ciphertext, the retractable cloud access control technology is realized, and the re-encryption process is performed by the cloud service provider, which reduces the encryption burden of the data owner. Experimental verification and analysis show that the proposed scheme has lower computational cost and higher security.
-
[1] 王于丁, 杨家海, 徐聪, 等. 云计算访问控制技术研究综述[J]. 软件学报, 2015, 26(5): 1129-1150. DOI: 10.13328/j.cnki.jos.004820.WANG Y D, YANG J H, XU C, et al. Survey on access control technologies for cloud computing[J]. Journal of Software, 2015, 26(5): 1129-1150. DOI: 10.13328/j.cnki.jos.004820. [2] SAHAI A, WATERS B. Fuzzy identity-based encryption[C]//Proceedings of the 24th International Conference on the Theory and Applications of Cryptographic Techniques. Aarhus, Denmark: Springer, 2005. DOI: 10.1007/11426639_27. [3] 王悦, 樊凯. 隐藏访问策略的高效CP-ABE方案[J]. 计算机研究与发展, 2019, 56(10): 2151-2159. DOI: 10.7544/issn1000-1239.2019.20190343.WANG Y, FAN K. Effective CP-ABE with hidden access policy[J]. Journal of Computer Research and Development, 2019, 56(10): 2151-2159. DOI: 10.7544/issn1000-1239.2019.20190343. [4] ZHAO Y, REN M, JIANG S Q, et al. An efficient and revocable storage CP-ABE scheme in the cloud computing[J]. Computing, 2019, 101(8): 1041-1065. DOI: 10.1007/s00607-018-0637-2. [5] 郑良汉, 何亨, 童潜, 等. 云环境中的多授权机构访问控制方案[J]. 计算机科学与探索, 2020, 14(11): 1865-1878. DOI: 10.3778/j.issn.1673-9418.1911020.ZHENG H L, HE H, TONG Q, et al. Multi-authority access control scheme in cloud environment[J]. Journal of Frontiers of Computer Science and Technology, 2020, 14(11): 1865-1878. DOI: 10.3778/j.issn.1673-9418.1911020. [6] 刘敖迪, 杜学绘, 王娜, 等. 基于区块链的大数据访问控制机制[J]. 软件学报, 2019, 30(9): 2636-2654. DOI: 10.13328/j.cnki.jos.005771.LIU A D, DU X H, WANG N, et al. Blockchain-based access control mechanism for big data[J]. Journal of Software, 2019, 30(9): 2636-2654. DOI: 10.13328/j.cnki.jos.005771. -