通信学报 ›› 2020, Vol. 41 ›› Issue (6): 184-201.doi: 10.11959/j.issn.1000-436x.2020088

• 学术通信 • 上一篇    下一篇

基于L-DHT的多租户虚拟域隔离构建方法

曹利峰,卢新(),高振升,杜学绘   

  1. 信息工程大学密码工程学院,河南 郑州 450001
  • 修回日期:2020-04-07 出版日期:2020-06-25 发布日期:2020-07-04
  • 作者简介:曹利峰(1981- ),男,河南禹州人,信息工程大学副教授,主要研究方向为网络安全、信息安全等|卢新(1995- ),男,山东济南人,信息工程大学硕士生,主要研究方向为信息安全、云计算安全|高振升(1995- ),男,河南洛阳人,信息工程大学硕士生,主要研究方向为信息安全、区块链安全|杜学绘(1968- ),女,博士,河南辉县人,信息工程大学教授,主要研究方向为信息安全、空天网络安全、云计算与大数据安全
  • 基金资助:
    国家自然科学基金资助项目(61502531);国家自然科学基金资助项目(61702550);国家重点研发计划基金资助项目(2018YFB0803603);国家重点研发计划基金资助项目(2016YFB0501901)

Multi-tenant virtual domain isolation construction method based on L-DHT

Lifeng CAO,Xin LU(),Zhensheng GAO,Xuehui DU   

  1. College of Cryptogram Engineering,Information Engineering University,Zhengzhou 450001,China
  • Revised:2020-04-07 Online:2020-06-25 Published:2020-07-04
  • Supported by:
    The National Natural Science Foundation of China(61502531);The National Natural Science Foundation of China(61702550);The National Key Research and Development Program of China(2018YFB0803603);The National Key Research and Development Program of China(2016YFB0501901)

摘要:

针对云环境下多租户数据的安全隔离的问题,提出了一种基于 L-DHT 的多租户虚拟域隔离构建方法。首先,通过设计一种基于标签 Hash 映射的多租户隔离映射算法,构建了租户资源的均衡映射机制,实现对租户资源的分布式管理;然后,针对映射到同一存储节点上租户数据间的安全隔离与访问,基于谓词加密机制,通过安全标签和租户数据的有效绑定,给出了一种基于标签谓词加密的租户数据隔离存储算法;最后,通过设计多维度的租户数据隔离控制规则,利用对安全标签的解析与认证,层次化地构建起租户间相互独立、逻辑、安全的虚拟域。安全性分析表明,所提方法构建了相互间安全无干扰的租户虚拟域。仿真实验结果表明,映射算法能够更好地实现负载的动态平衡,并通过数据检索效率与访问安全性的对比分析,验证了租户访问数据的安全性与高效性。

关键词: 租户虚拟域, 域隔离器, 安全标签, 多租户映射, 数据隔离

Abstract:

Aiming at the problem of security isolation of multi-tenant data in cloud environment,a tenant virtual domain isolation construction method based on L-DHT was proposed.Firstly,through the design of multi-tenant isolation mapping algorithm based on label-hash mapping,the balanced mapping mechanism of tenant resources was constructed to realize the distributed management of tenant resources.Secondly,for the security isolation and access between tenant data mapped to the same storage node,based on the predicate encryption mechanism,through the effective binding of security labels and tenant data,a tenant data isolation storage algorithm based on label predicate encryption was designed.Finally,by the design of multi-dimensional tenant data isolation control rules and using the analysis and authentication of security labels,independent,logical and secure virtual domains between tenants were built hierarchically.The security analysis shows that the method constructs tenant virtual domains which are secure and non-interference with each other.The simulation results show that the mapping algorithm can achieve a better dynamic load balance.The efficiency and security of data access are verified by the comparative analysis of tenant data retrieval efficiency and authentication access security.

Key words: tenant virtual domain, domain isolator, security label, multi-tenant mapping, data isolation

中图分类号: 

No Suggested Reading articles found!