高级检索

    数据空间中可比较属性的数据访问控制方案

    Data access control with comparable attribute for dataspace

    • 摘要: 数据是数字经济的关键生产要素和重要发展引擎,其共享和流通能够促进数据要素价值有效释放和数字经济高质量发展。数据空间是实现数据有效共享和流通的重要基础设施。但是,数据共享过程中面临的隐私泄露、数据窃取和非法滥用等问题给数据空间带来巨大挑战。属性基加密能够确保共享数据的机密性和细粒度访问控制,但直接将其应用于数据空间还存在许多问题。首先,传统属性基加密方案在用户撤销时计算开销较大,无法满足数据空间中大量动态用户加入或退出的场景。其次,许多行业数据空间需要根据用户属性比较和访问时间对其共享数据进行灵活的访问控制,并且能够对解密结果进行验证。为解决上述问题,提出一种数据空间中基于可比较属性的数据访问控制方案,实现了灵活高效的用户撤销以确保前向安全性,能够根据访问时间和属性比较来对其访问行为进行灵活决策,并支持对解密过程的验证。经过形式化安全分析,该方案在选择明文攻击下具有语义安全性。大量的实验分析表明该方案在性能上适用于实际的数据空间

       

      Abstract: Data is the key production factor and important driving force for digital economy. Its sharing and circulation can promote release of the value of data elements and high-quality development of digital economy. Dataspace is an important infrastructure for effective data sharing and circulation. However, privacy leakage, data theft, illegal abuse, etc. during data sharing pose significant challenges to dataspace. Attribute-based Encryption can ensure data confidentiality and fine-grained access control, but still faces many challenges when applied directly to dataspace. Firstly, the dynamic users in dataspace pose difficulties in terms of forward security. Secondly, many industry dataspaces need to perform flexible access control on shared data based on comparable attributes and access time, with decryption result verification. To address these issues, a data access control scheme based on comparable attribute for dataspace is proposed. It achieves flexible and efficient user revocation to ensure forward security by puncturable encryption, and can make flexible decisions on users' access behaviors based on access time and comparable attribute. It also supports verification of the decryption process. After formal security analysis, the scheme has semantic security under chosen plaintext attack. Extensive experimental analyses show that the scheme is suitable for actual dataspace

       

    /

    返回文章
    返回