云计算因具有资源利用率高、节约成本等诸多优点而将成为未来的主流计算模式.然而,包括隐私保护在内的数据安全存储问题却成为云计算推广的巨大障碍.该文首先列举了云计算在数据安全上面临的主要挑战,指出了云计算的租用商业模式和其采用的两种关键技术——虚拟化技术和多租户技术是云存储存在诸多安全问题甚至安全悖论的根本原因.从加密存储、安全审计和密文访问控制3个方面对云数据安全存储的最新研究进展分别进行了评述.在加密存储上,介绍了云数据安全存储框架和主要的安全存储技术;在安全审计上,分析了外包数据安全审计,特别是公开审计面临的主要难题,介绍了包括云数据在内的外包数据完整性公开证明的主要模型和方法,并指出了它们的优势和不足;在云密文的访问控制上,详述了基于属性的云密文访问控制方法,并指出了这些方法的优劣.最后指出了云数据安全存储研究面临的主要问题并预测了相关研究的未来发展趋势.
Cloud computing will become the main computing model in the future due to its advantages such as high resource utilization rate and high cost performance.How to securely store data including privacy data,however,becomes a huge impediment to its development.In this paper,the challenges,which cloud computing is confronted with,are listed first.The renting mode of cloud computing and its two key techniques,i.e.the virtualization and multi-tenant,are identified to result in these problems.And then the recent studies on cloud storage are reviewed in terms of cipher storage,security audit and cipher access control.The focuses involve in the framework and key techniques of cloud data storage,the problems and methods of security audit,and attribute-based access control methods as well as advantages and disadvantages of these techniques and methods.At last,the problems that the study of secure cloud storage is confronted with are identified,and further,the study trend of secure storage for cloud data is analyzed and predicted.