一种用于私有云存储中文档共享的数字信封方案

Jedidiah Yanez-Sierra, A. Díaz-Pérez, V. Sosa-Sosa, J. L. Gonzalez
{"title":"一种用于私有云存储中文档共享的数字信封方案","authors":"Jedidiah Yanez-Sierra, A. Díaz-Pérez, V. Sosa-Sosa, J. L. Gonzalez","doi":"10.1109/CEWIT.2015.7338158","DOIUrl":null,"url":null,"abstract":"Data assurance is one of the biggest concerns in adopting Cloud Computing. In Cloud Storage environment organizations outsource the storage and management of their documents for great flexibility and economic savings. However, contracting data storage to a third-party even in private cloud deployment could lead to potential security and privacy risks. Encryption of remotely stored documents before outsourced to the cloud has been the most widely used technique to bridge the privacy gap, nevertheless, this technique impose important limitations when users want to have workflows for sharing documents with others users, because data must be decrypted by the cloud storage before being sent or the private keys used to encrypt the documents must be shared. Both cases may lead to a lack of access control to the information. In this paper we present a digital envelope scheme over a configurable workflow architecture allowing secure document sharing in private cloud storage environments. Our scheme uses three main ideas: the encryption of the main information by using cryptographic systems, the construction of a documentsharing envelope by using attribute based encryption and digital signature mechanisms, and the development of a well-defined assurance workflow to transport the information through the different security phases. Based on our scheme, we developed a prototype and conducted a proof of concept in a private cloud environment. Experimental results revealed that the overhead of the assurance represents in average only a fraction (no more than 15%) of the sharing operations.","PeriodicalId":153787,"journal":{"name":"2015 12th International Conference & Expo on Emerging Technologies for a Smarter World (CEWIT)","volume":"11 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-12-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"A digital envelope scheme for document sharing in a private cloud storage\",\"authors\":\"Jedidiah Yanez-Sierra, A. Díaz-Pérez, V. Sosa-Sosa, J. L. Gonzalez\",\"doi\":\"10.1109/CEWIT.2015.7338158\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Data assurance is one of the biggest concerns in adopting Cloud Computing. In Cloud Storage environment organizations outsource the storage and management of their documents for great flexibility and economic savings. However, contracting data storage to a third-party even in private cloud deployment could lead to potential security and privacy risks. Encryption of remotely stored documents before outsourced to the cloud has been the most widely used technique to bridge the privacy gap, nevertheless, this technique impose important limitations when users want to have workflows for sharing documents with others users, because data must be decrypted by the cloud storage before being sent or the private keys used to encrypt the documents must be shared. Both cases may lead to a lack of access control to the information. In this paper we present a digital envelope scheme over a configurable workflow architecture allowing secure document sharing in private cloud storage environments. Our scheme uses three main ideas: the encryption of the main information by using cryptographic systems, the construction of a documentsharing envelope by using attribute based encryption and digital signature mechanisms, and the development of a well-defined assurance workflow to transport the information through the different security phases. Based on our scheme, we developed a prototype and conducted a proof of concept in a private cloud environment. Experimental results revealed that the overhead of the assurance represents in average only a fraction (no more than 15%) of the sharing operations.\",\"PeriodicalId\":153787,\"journal\":{\"name\":\"2015 12th International Conference & Expo on Emerging Technologies for a Smarter World (CEWIT)\",\"volume\":\"11 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-12-03\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 12th International Conference & Expo on Emerging Technologies for a Smarter World (CEWIT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CEWIT.2015.7338158\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 12th International Conference & Expo on Emerging Technologies for a Smarter World (CEWIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CEWIT.2015.7338158","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

数据保证是采用云计算的最大问题之一。在云存储环境中,组织将其文档的存储和管理外包,以获得极大的灵活性和经济节约。但是,即使在私有云部署中,将数据存储承包给第三方也可能导致潜在的安全和隐私风险。在外包给云之前对远程存储的文档进行加密一直是最广泛使用的弥合隐私鸿沟的技术,然而,当用户希望拥有与其他用户共享文档的工作流时,这种技术会带来重要的限制,因为数据在发送之前必须由云存储解密,或者用于加密文档的私钥必须共享。这两种情况都可能导致缺乏对信息的访问控制。在本文中,我们提出了一种基于可配置工作流架构的数字信封方案,允许在私有云存储环境中安全共享文档。我们的方案使用了三个主要思想:使用加密系统对主要信息进行加密,使用基于属性的加密和数字签名机制构建文档共享信封,以及开发定义良好的保证工作流来通过不同的安全阶段传输信息。基于我们的方案,我们开发了一个原型,并在私有云环境中进行了概念验证。实验结果表明,保证的开销平均只占共享操作的一小部分(不超过15%)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A digital envelope scheme for document sharing in a private cloud storage
Data assurance is one of the biggest concerns in adopting Cloud Computing. In Cloud Storage environment organizations outsource the storage and management of their documents for great flexibility and economic savings. However, contracting data storage to a third-party even in private cloud deployment could lead to potential security and privacy risks. Encryption of remotely stored documents before outsourced to the cloud has been the most widely used technique to bridge the privacy gap, nevertheless, this technique impose important limitations when users want to have workflows for sharing documents with others users, because data must be decrypted by the cloud storage before being sent or the private keys used to encrypt the documents must be shared. Both cases may lead to a lack of access control to the information. In this paper we present a digital envelope scheme over a configurable workflow architecture allowing secure document sharing in private cloud storage environments. Our scheme uses three main ideas: the encryption of the main information by using cryptographic systems, the construction of a documentsharing envelope by using attribute based encryption and digital signature mechanisms, and the development of a well-defined assurance workflow to transport the information through the different security phases. Based on our scheme, we developed a prototype and conducted a proof of concept in a private cloud environment. Experimental results revealed that the overhead of the assurance represents in average only a fraction (no more than 15%) of the sharing operations.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信