通信学报 ›› 2017, Vol. 38 ›› Issue (7): 1-10.doi: 10.11959/j.issn.1000-436x.2017138

• 学术论文 •    下一篇

基于封闭环境加密的云存储方案

杜瑞忠1,2,王少泫1,2,田俊峰1,2   

  1. 1 河北大学计算机科学与技术学院,河北 保定 071002
    2 河北省高可信信息系统重点实验室,河北 保定 071002
  • 修回日期:2017-03-30 出版日期:2017-07-01 发布日期:2017-08-25
  • 作者简介:杜瑞忠(1975-),男,河北献县人,博士,河北大学教授、硕士生导师,主要研究方向为可信计算与信息安全等。|王少泫(1990-),男,河北涉县人,河北大学硕士生,主要研究方向为可信计算与信息安全等。|田俊峰(1975-),男,河北蠡县人,博士,河北大学教授、博士生导师,主要研究方向为分布计算、可信计算与信息安全。
  • 基金资助:
    国家自然科学基金资助项目(61170254);国家自然科学基金资助项目(60873203);河北省自然科学基金资助项目(F2014201098);河北省高等学校科学技术研究基金资助项目(ZD2016043);河北省物联网数据采集与处理工程技术研究中心基金资助项目(Hebei 065201)

Cloud storage scheme based on closed-box encryption

Rui-zhong DU1,2,Shao-xuan WANG1,2,Jun-feng TIAN1,2   

  1. 1 College of Computer Science and Technology,Hebei University,Baoding 071002,China
    2 Key Lab on High Trusted Information System in Hebei Province,Baoding 071002,China
  • Revised:2017-03-30 Online:2017-07-01 Published:2017-08-25
  • Supported by:
    The National Natural Science Foundation of China(61170254);The National Natural Science Foundation of China(60873203);The Natural Science Foundation of Hebei Province(F2014201098);The Science and Technology Research Project in Colleges and Universities of Hebei Province(ZD2016043);Hebei Engineering Technology Research Center for IoT Data Acquisition & Processing,North China Insitute of Science and Technology(Hebei 065201)

摘要:

针对保护云存储中用户数据机密性的问题,提出了一种在云服务提供商处加密数据的云存储方案。通过虚拟机隔离技术来构造封闭计算环境,改进 RSA 公钥加密算法使其不需要重新产生大素数就能实现密钥变化,并通过SSL安全链接传输数据以及密钥,将数据在封闭计算环境中安全加密后再存储至分布式文件系统。封闭计算环境能阻止操作系统中不良应用以及云管理员的攻击,有效防范数据泄露。实验结果表明,用户数据的机密性得到了提升,并且相较于其他在云端加密的云存储方案,所提方案所带来的性能损耗降低了许多。

关键词: 云存储, 分布式文件系统, 封闭计算环境, RSA

Abstract:

Aiming at protecting the confidentiality of data for cloud storage users,a scheme that encrypt data in cloud service providers was presented.The scheme constructed a closed-box computing environment by virtual machine isolation technique,improved algorithm of RSA to change keys without having to produce large prime numbers,transfer data and keys through SSL and encrypted data in the closed computing environment before storing to the distributed file system.Closed-box computing environment can prevent attacks from cloud administrators and malicious applications in the operating system.It also can guard against data leakage effectively.The result of experiment shows that the confidentiality of data improved and the performance loss is decreased considering to other cloud storage scheme that encrypt data in cloud.

Key words: cloud storage, distributed file system, closed-box computing environment, RSA

中图分类号: 

No Suggested Reading articles found!