论文标题

确保组织的数据:有效解密的基于角色的授权关键字搜索方案

Securing Organization's Data: A Role-Based Authorized Keyword Search Scheme with Efficient Decryption

论文作者

Sultan, Nazatul Haque, Laurent, Maryline, Varadharajan, Vijay

论文摘要

为了获得更好的数据可用性和可访问性,在确保数据保密的同时,组织通常倾向于将其加密数据外包给云存储服务器,从而使关键字搜索的挑战超过了加密数据。在本文中,我们在云环境中使用基于角色的加密(RBE)技术提出了一种新颖的授权关键字搜索方案。本文的贡献是多重的。首先,它提出了一个关键字搜索方案,该方案只能使授权的用户具有适当的分配角色,以将基于关键字的数据搜索功能委托给云提供商,而无需透露任何敏感信息。其次,它支持一个多组织云环境,在该环境中,用户可以与多个组织联系起来。第三,提出的方案提供了有效的解密,结合的关键字搜索和撤销机制。第四,拟议的计划以安全的方式将昂贵的加密操作外包给云。第五,我们提供了正式的安全分析,以证明所提出的方案在语义上是针对选定的明文和所选的关键字攻击的。最后,我们的绩效分析表明,所提出的方案适用于实际应用。

For better data availability and accessibility while ensuring data secrecy, organizations often tend to outsource their encrypted data to the cloud storage servers, thus bringing the challenge of keyword search over encrypted data. In this paper, we propose a novel authorized keyword search scheme using Role-Based Encryption (RBE) technique in a cloud environment. The contributions of this paper are multi-fold. First, it presents a keyword search scheme which enables only the authorized users, having proper assigned roles, to delegate keyword-based data search capabilities over encrypted data to the cloud providers without disclosing any sensitive information. Second, it supports a multi-organization cloud environment, where the users can be associated with more than one organization. Third, the proposed scheme provides efficient decryption, conjunctive keyword search and revocation mechanisms. Fourth, the proposed scheme outsources expensive cryptographic operations in decryption to the cloud in a secure manner. Fifth, we have provided a formal security analysis to prove that the proposed scheme is semantically secure against Chosen Plaintext and Chosen Keyword Attacks. Finally, our performance analysis shows that the proposed scheme is suitable for practical applications.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源