1. 西安电子科技大学计算机学院,西安,710071
2. 福建师范大学软件学院,福州,350108
网络首发:2014-02-10,
纸质出版:2014
移动端阅览
熊金波 1, 姚志强 1, 2, 等. 云计算环境中的组合文档模型及其访问控制方案[J]. 西安交通大学学报, 2014,48(2):25-31.
A Composite Document Model and Its Access Control Scheme in Cloud Computing[J]. 2014, 48(2): 25-31.
熊金波 1, 姚志强 1, 2, 等. 云计算环境中的组合文档模型及其访问控制方案[J]. 西安交通大学学报, 2014,48(2):25-31. DOI: 10.7652/xjtuxb201402005.
A Composite Document Model and Its Access Control Scheme in Cloud Computing[J]. 2014, 48(2): 25-31. DOI: 10.7652/xjtuxb201402005.
针对云计算环境缺乏有效的组合文档模型及其元素分级安全保护的现状
结合多级安全思想和基于身份的加密(IBE)算法
提出了一种新的组合文档模型(ComDoc)及其访问控制方案(ICDAC)。ComDoc包含组合文档的密文部分和密钥映射部分:前者保存具有安全等级的文档元素的密文; 后者保存由IBE加密的密钥映射记录密文。ICDAC依据授权用户的身份信息
利用IBE解密对应的记录后获得映射对
提取访问权限并解密授权的文档元素密文
实现组合文档元素分级安全保护的细粒度访问控制。实验结果表明:ComDoc满足云计算环境中组合文档的特征以及安全需求; 在加密相同组合文档的前提下
ICDAC的密钥数量和计算开销明显优于已有方案。
A composite document model(ComDoc)and its fine-grained access control scheme(ICDAC)are proposed to address the actualities of lack of effective composite document model and multilevel security protection for document elements in cloud computing. The model combines the idea of multilevel security with an identity-based encryption(IBE)algorithm. In ComDoc composite document consists of a ciphertext part and a key-map part. The former stores the ciphertexts of document elements with security level. The element names and corresponding keys constitute map pairs and map records
and the records are then encrypted by the IBE and stored in the latter. The ICDAC achieves fine-grained access control with multilevel security protection for document elements by the following strategy. Authorized user decrypts the corresponding map records to get map pairs under the IBE in terms of the identity
and to extract the decryption keys to obtain the plaintext of the document elements. Comprehensive analysis shows that ComDoc satisfies the composite document characteristics and security requirements in cloud computing. Experimental results show that both the key numbers and the computational overheads of ICDAC are superior to existing scheme on the premise of encrypting the same composite documents.
BALINKSY H, SIMSKE S J. Secure document engineering[C]∥Proceedings of the 11th ACM Symposium on Document Engineering. New York, USA: ACM, 2011: 269-272.
BALINKSY H, SIMSKE S J. Differential access for publicly-posted composite documents with multiple workflow participants[C]∥Proceedings of the 10th ACM Symposium on Document Engineering. New York, USA: ACM, 2010: 115-124.
熊金波, 姚志强, 马建峰, 等. 基于行为的结构化文档多级访问控制[J]. 计算机研究与发展, 2013, 50(7): 1399-1408.
XIONG Jinbo, YAO Zhiqiang, MA Jianfeng, et al. Action-based multilevel access control for structured document[J]. Journal of Computer Research and Development, 2013, 50(7): 1399-1408.
TAN S S, TANG E K, RANAIVO M B, et al. Modeling semantic correspondence in heterogeneous structured document collection[C]∥Proceedings of the 2011 International Conference on Semantic Technology and Information Retrieval. Los Alamitos, CA: IEEE Computer Society, 2011: 189-196.
衡星辰, 罗俊颉, 郭俊文, 等. 八邻域网格聚类的多样性 XML文档近似查询算法[J]. 西安交通大学学报, 2007, 41(8): 907-911.
HENG Xingchen, LUO Junjie, GUO Junwen, et al. Approximate query algorithm based on eight neighbor grid clustering for heterogeneous XML documents[J]. Journal of Xi'an Jiaotong University, 2007, 41(8): 907-911.
TEKLI J, CHBEIR R. A novel XML document structure comparison framework based on sub-tree commonalities and label semantics[J]. Web Semantics: Science, Services and Agents on the World Wide Web, 2012, 11(3): 14-40.
PORTIER P E, CHATTI N, CALABRETTO S, et al. Modeling, encoding and querying multi-structured documents[J]. Information Processing Management, 2012, 48(5): 931-955.
ZHENG S, LIU J. A secure confidential document model and its application[C]∥Proceedings of the International Conference on Multimedia Information Networking and Security. Piscataway, NJ, USA: IEEE Computer Society, 2010: 526-529.
BOLL S, KLAS W. ZYX: a multimedia document model for reuse and adaptation of multimedia content[J]. IEEE Transactions on Knowledge and Data Engineering, 2001, 13(3): 361-382.
BALINSKY H, CHEN L, SIMSKE S J. Publicly posted composite documents with identity based encryption[C]∥Proceedings of the 11th ACM Symposium on Document Engineering. New York, USA: ACM, 2011: 239-248.
熊金波, 姚志强, 金彪. 云计算环境中结构化文档形式化建模[J]. 计算机应用, 2013, 33(5): 1267-1270.
XIONG Jinbo, YAO Zhiqiang, JIN Biao. Formal modeling for structured document in cloud computing[J]. Journal of Computer Applications, 2013, 33(5): 1267-1270.
BONEH D, FRANKLIN M. Identity-based encryption from the Weil pairing[J]. SIAM Journal on Computing, 2003, 32(3): 586-615.
XIONG J B, YAO Z Q, MA J F, et al. A secure document self-destruction scheme with identity based encryption[C]∥Proceedings of the 5th International Conference on Intelligent Networking and Collaborative Systems, IEEE INCoS'13. Los Alamitos, CA, USA: IEEE CS, 2013: 239-243.
刘西蒙, 马建峰, 熊金波, 等. 密文策略的权重属性基加密方案[J]. 西安交通大学学报, 2013, 47(8): 44-48.
LIU Ximeng, MA Jianfeng, XIONG Jinbo, et al. Ciphertext policy weighted attribute based encryption scheme[J]. Journal of Xi'an Jiaotong University, 2013, 47(8): 44-48.
LYNN B. The Pairing-based cryptography library[EB/OL].[2013-04-20]. http:∥www.crypto.stanford.edu/pbc/dounload.html.
0
浏览量
4
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621