云存储中多授权多关键字属性基可搜索加密方案OA
Attribute-Based Multi-authority Multi-keyword Searchable Encryption Scheme for Cloud Storage
为了保护云服务器中存储隐私数据的安全性,通常采用加密的方式对敏感数据进行处理.然而,云中密态数据不利于用户进行后续的检索与共享.与此同时,未经授权的访问会造成用户数据隐私泄露,并且传统的单授权机制存在性能瓶颈与单点故障风险.为解决以上问题,提出一种适用于云存储的多授权多关键字属性基可搜索加密方案.采用密文策略属性加密(CP-ABE)来为系统中的数据提供机密性保护,实现数据的细粒度访问控制.引入在线/离线加密技术,将复杂运算如对称密钥生成、访问策略矩阵M的份额计算及密文组件的生成设计在离线阶段运行,在线加密阶段仅需执行点乘运算,即可生成最终密文,降低了用户客户端在线加密的计算开销.使用密码累加器生成关键字索引,并在搜索阶段对用户上传的关键字进行验证,从而减少复杂的密码学计算,提高方案运行效率.在用户解密阶段添加对结果验证的过程,根据属性和访问策略判断返回的结果是否正确,确保云服务器返回数据的完整性和正确性.在安全性方面,证明了方案在选择关键字不可区分下的安全性.对方案进行仿真模拟,实验结果表明提出的方案相比同类方案,在索引生成、陷门生成以及搜索阶段的效率分别实现了52.34%、62.23%、53.97%的提升.
To protect the security of private data stored in cloud servers,encryption is commonly used to process sensitive data.However,ciphertext data in the cloud impedes subsequent retrieval and sharing by users.Meanwhile,unauthorized access may cause privacy leakage of user data,and the traditional single-authorization mechanism is faced with perfor-mance bottlenecks and single point of failure risks.To solve the above problems,this paper proposes a multi-authority multi-keyword attribute-based searchable encryption scheme for cloud storage.Ciphertext-policy attribute-based encryption(CP-ABE)is adopted to ensure data confidentiality and implement fine-grained access control in the system.In addition,online/offline encryption technology is introduced.Complex operations such as symmetric key generation,share calculation of access policy matrix M and ciphertext component generation are executed in the offline phase,while only dot product operations are needed in the online encryption phase to generate the final ciphertext,which reduces the online encryption computational overhead on user clients.A cryptographic accumulator is used to construct keyword indices and verify key-words submitted by users during the search process,lowering the cost of complex cryptographic computations and improving the operational efficiency of the scheme.A result verification process is also added in the user decryption phase.The correctness of returned results is judged based on user attributes and access policies,so as to guarantee the integrity and validity of data returned by cloud servers.In terms of security,the proposed scheme is proven secure under selective keyword indistinguishability.Finally,simulation experiments are carried out.Experimental results demonstrate that compared with similar existing schemes,the proposed scheme improves the efficiency by 52.34%,62.23%and 53.97%in the stages of index generation,trapdoor generation and search respectively.
谭越文;郭瑞;孙博;刘光军
西安邮电大学 网络空间安全学院,西安 710121||西安邮电大学 无线网络安全技术国家工程研究中心,西安 710121西安邮电大学 网络空间安全学院,西安 710121||西安邮电大学 无线网络安全技术国家工程研究中心,西安 710121西安邮电大学 网络空间安全学院,西安 710121||西安邮电大学 无线网络安全技术国家工程研究中心,西安 710121西安文理学院 信息工程学院,西安 710065
信息技术与安全科学
可搜索加密属性加密细粒度访问控制密码累加器
searchable encryptionattribute-based encryptionfine-grained access controlcryptographic accumulator
《计算机科学与探索》 2026 (7)
1985-1996,12
国家密码科学基金(2025NCSF02037)国家自然科学基金(62072369)陕西省重点研发计划基金(2020ZDLGY08-04)陕西省创新能力支持计划基金(2020KJXX-052)陕西省自然科学基金一般项目(2024JC-YBMS-545,2024JC-YBMS-557)陕西省高校青年创新团队项目(23JP160)西安市科技计划项目(23KGDW0018-2023). This work was supported by the National Cryptologic Science Fund of China(2025NCSF02037),the National Natural Science Foundation of China(62072369),the Shaanxi Provincial Key Research and Development Program(2020ZDLGY08-04),the Innovation Capacity Support Program of Shaanxi Province(2020KJXX-052),the General Program of Natural Science Foundation of Shaanxi Province(2024JC-YBMS-545,2024JC-YBMS-557),the Youth Innovation Team Project of Shaanxi Universities(23JP160),and the Science and Technology Program of Xi'an(23KGDW0018-2023).
评论