天堂国产午夜亚洲专区-少妇人妻综合久久蜜臀-国产成人户外露出视频在线-国产91传媒一区二区三区

當前位置:主頁 > 科技論文 > 計算機論文 >

對象存儲系統(tǒng)中數(shù)據(jù)私密性保護與共享

發(fā)布時間:2018-07-28 11:10
【摘要】:隨著數(shù)據(jù)價值不斷提升,分布式存儲系統(tǒng)中的數(shù)據(jù)加密存儲變得更為重要。為降低對存儲系統(tǒng)的信任,以滿足對用戶隱私保護的需求,端對端的加密存儲應運而生。對象存儲設(shè)備因其智能管理數(shù)據(jù)的特征,被海量信息存儲領(lǐng)域普遍應用。對象存儲系統(tǒng)的安全方面,,大部分研究是針對認證和授權(quán),但如何保證數(shù)據(jù)在傳輸和存儲中的安全,以及如何將數(shù)據(jù)安全共享給用戶仍是亟待解決的問題。 在基于身份的安全對象存儲系統(tǒng)中,文件被加密后以密文形式存儲及傳輸,實現(xiàn)了端對端的數(shù)據(jù)機密性保護;谏矸莸募用芊绞絀BE,使用身份信息作為公鑰,降低了PKI公鑰管理的復雜度。IBE方式加密保護數(shù)據(jù)密鑰SK,只有相應的私鑰可解密得到數(shù)據(jù)密鑰并能夠正確訪問文件內(nèi)容。同時,結(jié)合基于角色的訪問控制機制,有效管理共享密鑰FK。引入角色證書,同一角色具有相同的訪問權(quán)限及共享密鑰,F(xiàn)K與訪問權(quán)限控制項一起被視為數(shù)據(jù)的安全屬性,減少安全元數(shù)據(jù)列表的冗余信息,實現(xiàn)了共享密鑰的高效查找及更新。HMAC-SHA1消息認證協(xié)議使用數(shù)據(jù)密鑰SK作為隨機密鑰,提供數(shù)據(jù)完整性保護。引入緩存機制,有效緩存高頻率被訪問的內(nèi)容,節(jié)省了獲取元數(shù)據(jù)的時間及避免重復加解密操作,提高了系統(tǒng)性能。 測試表明,系統(tǒng)提供了有效的密鑰保護與共享機制,且安全開銷控制在合理的范圍內(nèi),完整性保護開銷不超過15%,加密開銷控制在25%以內(nèi)。
[Abstract]:With the increasing value of data, the data encryption storage in distributed storage system becomes more and more important. In order to reduce the trust of storage system to meet the need of privacy protection, end-to-end encrypted storage came into being. Object storage devices are widely used in the field of mass information storage because of their characteristics of intelligent management data. In the security aspect of object storage system, most of the researches focus on authentication and authorization, but how to ensure the security of data transmission and storage, and how to share data security with users is still an urgent problem to be solved. In an identity-based secure object storage system, files are encrypted and stored and transmitted in ciphertext form, which realizes end-to-end data confidentiality protection. Ibe, an identity-based encryption method, uses identity information as the public key, which reduces the complexity of PKI public key management. Ibe can encrypt and protect the data key SKK. Only the corresponding private key can be decrypted to obtain the data key and the file contents can be accessed correctly. At the same time, combining the role-based access control mechanism, the shared key FK is managed effectively. By introducing the role certificate, the same role has the same access rights and the shared key FK is regarded as the security attribute of the data together with the access rights control item, which reduces the redundant information in the security metadata list. The efficient search and update of the shared key. HMAC-SHA1 message authentication protocol uses the data key SK as the random key to provide data integrity protection. The cache mechanism is introduced to cache the contents accessed with high frequency effectively, which saves the time of obtaining metadata, avoids repeated encryption and decryption operations, and improves the system performance. The test results show that the system provides an effective key protection and sharing mechanism, and the security cost is controlled within a reasonable range, the integrity protection cost is not more than 15%, and the encryption cost is less than 25%.
【學位授予單位】:華中科技大學
【學位級別】:碩士
【學位授予年份】:2012
【分類號】:TP333;TP309.2

【參考文獻】

相關(guān)期刊論文 前1條

1 李新國,葛建華,趙春明;IBE公鑰加密系統(tǒng)的用戶私鑰分發(fā)方案[J];西安電子科技大學學報;2004年04期



本文編號:2149934

資料下載
論文發(fā)表

本文鏈接:http://sikaile.net/kejilunwen/jisuanjikexuelunwen/2149934.html


Copyright(c)文論論文網(wǎng)All Rights Reserved | 網(wǎng)站地圖 |

版權(quán)申明:資料由用戶ad2ed***提供,本站僅收錄摘要或目錄,作者需要刪除請E-mail郵箱bigeng88@qq.com