随着移动终端多媒体技术的发展,用户逐渐将本地数据通过各种网络备份到云存储服务器上.云平台在提供廉价便捷的数据存储服务的同时也存在数据安全防护问题,尤其是密文数据访问控制完全依赖于云服务商.为了防止数据被非授权用户和半可信云存储提供商的非法访问,提出一种基于节点映射关系的CP-ABE属性加密算法,即通过属性管理降低权限管理的复杂度.在密文访问控制机制中引入密钥授权中心和安全代理实现存储服务与安全服务异地存储,保证在开放环境下云存储系统中数据的安全性.实验结果表明,这种属性管理机制在少量的系统开销下实现了数据存储与密钥存储的分离,具有较高的应用价值.
With the development of mobile technology, more and more people use cloud storage to back up their local data. The cloud platforms provide cheap and convenient data storage services while there are serious data security problems, especially the ciphertext data access control being totally dependent on the cloud provider. An advanced CP-ABE scheme based on mapping nodes was presented to prevent illegal access from unauthorized users or partially trusted cloud storage providers. In order to guarantee the security of cloud data in open environment, Key Generation Center and Security Proxy are introduced to separate the data service and security service in the access scheme. Experimental results show that the proposed attribute management scheme is capable of separating the secret key from data service at a low computational cost, showing great potential for applications.