为解决云计算环境下文件共享的安全问题,Hong等人[1]提出了一种基于CP-ABE(Ciphertext-policy attributed-based encrtption)密文策略的动态密文访问控制方法 HCRE,将访问控制结构转移到云端,实现高效的共享访问控制。针对该方案在用户访问权限撤销过程中存在严重的安全漏洞,通过给出实际的攻击案例不但指出该漏洞所在,而且分析其成因,并结合代理重加密提出一种新的改进方案。其在继承HCRE方案优点的同时,还弥补了安全漏洞,且在权限撤销阶段更具效率。
To solve security problem of file sharing in cloud computing environment,Hong et al.[1]proposed a CP-ABE ciphertext strategy-based dynamic cryptographic access control method,named HCRE,it transfers the access control structure to cloud side,and achieves efficient sharing access control. But in the process of revoking user's access privileges,HCRE has serious security vulnerability. In light of this,by giving the actual attack case we point out where the vulnerability is,and analyse the causes of it as well,furthermore we propose an improved scheme in combination with the proxy re-encryption. While inheriting the advantages of HCRE,it also makes up the security vulnerabilities,and is more efficient in the process of revoking privileges.