Xiao Min, Zhou Jing, Liu Xuejiao, Jiang Mingda
School of Cyber Security and Information Law, Chongqing University of Posts and Telecommunicaitons, Chongqing 400065, China.
College of Computer Science and Technology, Chongqing University of Posts and Telecommunicaitons, Chongqing 400065, China.
Sensors (Basel). 2017 Jun 17;17(6):1423. doi: 10.3390/s17061423.
In the fog computing environment, the encrypted sensitive data may be transferred to multiple fog nodes on the edge of a network for low latency; thus, fog nodes need to implement a search over encrypted data as a cloud server. Since the fog nodes tend to provide service for IoT applications often running on resource-constrained end devices, it is necessary to design lightweight solutions. At present, there is little research on this issue. In this paper, we propose a fine-grained owner-forced data search and access authorization scheme spanning user-fog-cloud for resource constrained end users. Compared to existing schemes only supporting either index encryption with search ability or data encryption with fine-grained access control ability, the proposed hybrid scheme supports both abilities simultaneously, and index ciphertext and data ciphertext are constructed based on a single ciphertext-policy attribute based encryption (CP-ABE) primitive and share the same key pair, thus the data access efficiency is significantly improved and the cost of key management is greatly reduced. Moreover, in the proposed scheme, the resource constrained end devices are allowed to rapidly assemble ciphertexts online and securely outsource most of decryption task to fog nodes, and mediated encryption mechanism is also adopted to achieve instantaneous user revocation instead of re-encrypting ciphertexts with many copies in many fog nodes. The security and the performance analysis show that our scheme is suitable for a fog computing environment.
在雾计算环境中,加密的敏感数据可能会被传输到网络边缘的多个雾节点以实现低延迟;因此,雾节点需要像云服务器一样对加密数据进行搜索。由于雾节点倾向于为通常在资源受限的终端设备上运行的物联网应用提供服务,所以有必要设计轻量级的解决方案。目前,针对这个问题的研究很少。在本文中,我们针对资源受限的终端用户提出了一种跨用户 - 雾 - 云的细粒度所有者强制数据搜索和访问授权方案。与现有的仅支持具有搜索能力的索引加密或具有细粒度访问控制能力的数据加密的方案相比,所提出的混合方案同时支持这两种能力,并且索引密文和数据密文基于单个基于密文策略的属性加密(CP - ABE)原语构建并共享相同的密钥对,从而显著提高了数据访问效率并大大降低了密钥管理成本。此外,在所提出的方案中,允许资源受限的终端设备在网上快速组装密文并将大部分解密任务安全地外包给雾节点,并且还采用了中介加密机制来实现即时的用户撤销,而不是在许多雾节点中对多个副本的密文进行重新加密。安全性和性能分析表明,我们的方案适用于雾计算环境。