A composite document model(ComDoc)and its fine-grained access control scheme(ICDAC)are proposed to address the actualities of lack of effective composite document model and multilevel security protection for document elements in cloud computing. The model combines the idea of multilevel security with an identity-based encryption(IBE)algorithm. In ComDoc composite document consists of a ciphertext part and a key-map part. The former stores the ciphertexts of document elements with security level. The element names and corresponding keys constitute map pairs and map records
and the records are then encrypted by the IBE and stored in the latter. The ICDAC achieves fine-grained access control with multilevel security protection for document elements by the following strategy. Authorized user decrypts the corresponding map records to get map pairs under the IBE in terms of the identity
and to extract the decryption keys to obtain the plaintext of the document elements. Comprehensive analysis shows that ComDoc satisfies the composite document characteristics and security requirements in cloud computing. Experimental results show that both the key numbers and the computational overheads of ICDAC are superior to existing scheme on the premise of encrypting the same composite documents.
关键词
Keywords
references
BALINKSY H, SIMSKE S J. Secure document engineering[C]∥Proceedings of the 11th ACM Symposium on Document Engineering. New York, USA: ACM, 2011: 269-272.
BALINKSY H, SIMSKE S J. Differential access for publicly-posted composite documents with multiple workflow participants[C]∥Proceedings of the 10th ACM Symposium on Document Engineering. New York, USA: ACM, 2010: 115-124.
XIONG Jinbo, YAO Zhiqiang, MA Jianfeng, et al. Action-based multilevel access control for structured document[J]. Journal of Computer Research and Development, 2013, 50(7): 1399-1408.
TAN S S, TANG E K, RANAIVO M B, et al. Modeling semantic correspondence in heterogeneous structured document collection[C]∥Proceedings of the 2011 International Conference on Semantic Technology and Information Retrieval. Los Alamitos, CA: IEEE Computer Society, 2011: 189-196.
HENG Xingchen, LUO Junjie, GUO Junwen, et al. Approximate query algorithm based on eight neighbor grid clustering for heterogeneous XML documents[J]. Journal of Xi'an Jiaotong University, 2007, 41(8): 907-911.
TEKLI J, CHBEIR R. A novel XML document structure comparison framework based on sub-tree commonalities and label semantics[J]. Web Semantics: Science, Services and Agents on the World Wide Web, 2012, 11(3): 14-40.
PORTIER P E, CHATTI N, CALABRETTO S, et al. Modeling, encoding and querying multi-structured documents[J]. Information Processing Management, 2012, 48(5): 931-955.
ZHENG S, LIU J. A secure confidential document model and its application[C]∥Proceedings of the International Conference on Multimedia Information Networking and Security. Piscataway, NJ, USA: IEEE Computer Society, 2010: 526-529.
BOLL S, KLAS W. ZYX: a multimedia document model for reuse and adaptation of multimedia content[J]. IEEE Transactions on Knowledge and Data Engineering, 2001, 13(3): 361-382.
BALINSKY H, CHEN L, SIMSKE S J. Publicly posted composite documents with identity based encryption[C]∥Proceedings of the 11th ACM Symposium on Document Engineering. New York, USA: ACM, 2011: 239-248.
XIONG Jinbo, YAO Zhiqiang, JIN Biao. Formal modeling for structured document in cloud computing[J]. Journal of Computer Applications, 2013, 33(5): 1267-1270.
BONEH D, FRANKLIN M. Identity-based encryption from the Weil pairing[J]. SIAM Journal on Computing, 2003, 32(3): 586-615.
XIONG J B, YAO Z Q, MA J F, et al. A secure document self-destruction scheme with identity based encryption[C]∥Proceedings of the 5th International Conference on Intelligent Networking and Collaborative Systems, IEEE INCoS'13. Los Alamitos, CA, USA: IEEE CS, 2013: 239-243.
LIU Ximeng, MA Jianfeng, XIONG Jinbo, et al. Ciphertext policy weighted attribute based encryption scheme[J]. Journal of Xi'an Jiaotong University, 2013, 47(8): 44-48.
LYNN B. The Pairing-based cryptography library[EB/OL].[2013-04-20]. http:∥www.crypto.stanford.edu/pbc/dounload.html.