通信学报 ›› 2014, Vol. 35 ›› Issue (2): 95-103.doi: 10.3969/j.issn.1000-436x.2014.02.013

• 学术论文 • 上一篇    下一篇

云计算环境中支持隐私保护的数字版权保护方案

黄勤龙1,2,3,马兆丰1,2,3,傅镜艺1,2,3,杨义先1,2,钮心忻1,2   

  1. 1 北京邮电大学 信息安全中心,北京 100876;
    2 北京邮电大学 灾备技术国家工程实验室,北京 100876;
    3 北京国泰信安科技有限公司,北京 100086
  • 出版日期:2014-02-25 发布日期:2017-07-25
  • 基金资助:
    国家自然科学基金资助项目;国家自然科学基金资助项目;国家自然科学基金资助项目

Privacy-preserving digital rights management scheme in cloud computing

Qin-long HUANG1,2,3,Zhao-feng MA1,2,3,Jing-yi FU1,2,3,Yi-xian YANG1,2,Xin-xin NIU1,2   

  1. 1 Information Security Center, Beijing University of Posts and Telecommunications, Beijing 100876, China;
    2 National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and Telecommunications, Beijing 100876, China;
    3 Beijing National Security Science and Technology Co Ltd, Beijing 100086, China
  • Online:2014-02-25 Published:2017-07-25

摘要:

针对云计算环境中数字内容安全和用户隐私保护的需求,提出了一种云计算环境中支持隐私保护的数字版权保护方案。设计了云计算环境中数字内容版权全生命周期保护和用户隐私保护的框架,包括系统初始化、内容加密、许可授权和内容解密4个主要协议;采用基于属性基加密和加法同态加密算法的内容加密密钥保护和分发机制,保证内容加密密钥的安全性;允许用户匿名向云服务提供商订购内容和申请授权,保护用户的隐私,并且防止云服务提供商、授权服务器和密钥服务器等收集用户使用习惯等敏感信息。与现有的云计算环境中数字版权保护方案相比,该方案在保护内容安全和用户隐私的同时,支持灵活的访问控制,并且支持在线和超级分发应用模式,在云计算环境中具有较好的实用性。

关键词: 数字版权管理, 隐私保护, 属性基加密, 同态加密, ;云计算

Abstract:

In order to meet the needs of digital content and user privacy protection in cloud computing environment, a privacy-preserving digital rights management (DRM) scheme in cloud computing was proposed. The framework of digital content copyright lifecycle protection and user privacy protection in cloud computing was firstly designed, which includes four protocols: system setup, content encryption, license acquisition and content decryption, and then a content encryption key protection and distribution mechanism based on attribute-based encryption and additively homomorphic encryption was proposed, which ensures the security of content encryption key. In addition, the pro-posed scheme also allows the users to purchase content and acquire license anonymously from cloud service provider, which protects the user privacy and prevents cloud service provider, license server and key server in the cloud from collecting the user's sensitive information. Compared with existing DRM schemes in cloud computing, the proposed scheme which not only protects the data security and user privacy, but also supports fine-grained access control, and supports online and super-distribution application modes, is more applicable in the copyright protection for cloud computing.

Key words: digital rights management, privacy preserving, attribute-based encryption, homomorphic encryption, cloud computing

No Suggested Reading articles found!