用户数据在云存储环境下缺乏有效的数据销毁机制,其数据安全性在生命周期内面临威胁,销毁时间受控,大大限制了云存储服务的发展。为此,提出一种云存储环境下生命周期可控的数据销毁模型。首先,通过函数变换处理明文生成密文和元数据,避免复杂的密钥管理;其次,为提高数据销毁的可控性,设计一种基于时间可控的自销毁数据对象,使得过期数据的任何非法访问都会触发数据重写程序对自销毁数据对象进行确定性删除,从而实现生命周期可控的数据销毁功能。分析及实验结果表明,该方案在保护数据安全的同时,能够有效地销毁数据,增强数据销毁的灵活性、可控性,且具有较低的性能开销。
A data destruction model based on lifecycle control under cloud storage environment was proposed to solve the lack of effective data destruction mechanism for user data, and that data security was threatened and destruction time was controlled in the life cycle, which greatly limited the development of cloud services. The plain text was processed by functional transformation to generate the cipher text and metadata and avoid the complex key management. Secondly, in order to improve the controllability of data destruction, a serf-destruction data objects based on controllable time was designed, which made any illegal access of expired objects to trigger the assured deletion by rewriting program, and realized the data destruction based on lifecyele control. The analysis and experimental results show that the scheme can enhance the flexibility and controllability of data destruction and reduce the performance cost, while protecting the data safely and effectively.