通信学报 ›› 2019, Vol. 40 ›› Issue (1): 130-140.doi: 10.11959/j.issn.1000-436x.2019012

• 学术论文 • 上一篇    下一篇

基于覆写验证的云数据确定性删除方案

杜瑞忠1,石朋亮1,何欣枫1   

  1. 1 河北大学网络空间安全与计算机学院,河北 保定 071002
    2 河北省高可信信息系统重点实验室,河北 保定 071002
  • 修回日期:2018-10-31 出版日期:2019-01-01 发布日期:2019-02-03
  • 作者简介:杜瑞忠(1975- ),男,河北献县人,博士,河北大学教授,主要研究方向为可信计算与信息安全等。|石朋亮(1992- ),男,河北唐县人,河北大学硕士生,主要研究方向为可信计算与信息安全等。|何欣枫(1976- ),男,天津人,河北大学副教授,主要研究方向为云计算安全与可信计算等。
  • 基金资助:
    国家自然科学基金资助项目(61572170);河北省自然科学基金资助项目(F2018201153);河北省自然科学基金资助项目(2016205023);北省高等学校科学技术研究基金资助项目(ZD2016043);河北省物联网监控工程技术研究中心基金资助项目(3142016020)

Cloud data assured deletion scheme based on overwrite verification

Ruizhong DU1,Pengliang SHI1,Xinfeng HE1   

  1. 1 Cyberspace Security and Computer College,Hebei University,Baoding 071002,China
    2 Key Lab on High Trusted Information System in Hebei Province,Baoding 071002,China
  • Revised:2018-10-31 Online:2019-01-01 Published:2019-02-03
  • Supported by:
    The National Natural Science Foundation of China(61572170);The Natural Science Foundation of Hebei Province(F2018201153);The Natural Science Foundation of Hebei Province(2016205023);The Science and Technology Research Project in Colleges and Universities of Hebei Province(ZD2016043);Hebei IoT Monitoring Engineering Technology Research Center(3142016020)

摘要:

云存储中的数据在生命周期结束删除时,大多是采用删除密钥的逻辑删除方式进行处理,数据仍存在泄露风险,为此提出了一种基于密文重加密与覆写验证结合的云数据确定性删除方案(WV-CP-ABE)。当数据拥有者想删除外包数据时,通过重新加密密文改变密文对应的访问控制策略来实现数据细粒度删除操作;其次构建基于脏数据块覆写的可搜索路径散列二叉树(DSMHT),对要删除的数据进行覆写后正确性验证;最终采用更改密文访问控制策略和数据覆写双重机制保障数据确定性删除。实验分析证明,所提方案在数据确定性删除方面比以前的逻辑删除方法细粒度控制更好,安全性更可靠。

关键词: 云存储, 密文属性加密, 确定性删除, 散列二叉树, 覆写验证

Abstract:

At the end of data life cycle,there is still a risk of data leakage,because mostly data which was stored in cloud is removed by logical deletion of the key.Therefore,a cloud data assured deletion scheme (WV-CP-ABE) based on ciphertext re-encrypt and overwrite verification was proposed.When data owner wants to delete the outsourced data,the data fine-grained deletion operation was realized by re-encrypting the ciphertext to change the access control policy.Secondly,a searchable path hash binary tree (DSMHT) based on dirty data block overwrite was built to verify the correctness of the data to be deletion.Finally,the dual mechanism of changing the ciphertext access control policy and data overwriting guarantees the data assured deletion.The experimental analysis proves that the fine-grained control is better and the security is more reliable than the previous logical delete method in the assured deletion of data.

Key words: cloud storage, CP-ABE, assured deletion, Hash binary tree, overwrite and verify

中图分类号: 

No Suggested Reading articles found!