云环境下安全数据访问的增强密钥建立技术

Vidhisha Reddy, G. Prakash
{"title":"云环境下安全数据访问的增强密钥建立技术","authors":"Vidhisha Reddy, G. Prakash","doi":"10.1109/ICICT46931.2019.8977720","DOIUrl":null,"url":null,"abstract":"Today the IT environment concentrates on Cloud computing where the usage of cloud based applications poses various security threats. Many possible cloud applications fall victim to a tragedy of the generic approach such that a shared cloud service is becoming unstable and insecure based on the commercial demands by IT and other business organization. Companies should develop proper security guidelines for public and private cloud use and utilize an adequate cloud access model. Based on set of features in the three common cloud services, a set of security capabilities is identified which are needed to exercise those characteristic and the cryptographic dealing they entail. Random Number Generators can be used in cloud hosts especially for virtualized machines. Several purpose of Pseudo Random Number Generator (PRNG) exists in cloud which mainly can be used to authenticate users to the information stored on cloud, salts for the passwords or for statistical sampling. ANSI X9.31 is one standard pseudo random number generator used in many standard cryptographic algorithms like AES, RSA that are managed in securing data access in cloud applications. As ANSI X9.31 seed values are not secure they are directly used for generation. With brute force attack the seed values are exposed. On retrieval of seed values the key can be predicted which leads to insecurity of the information stored on the cloud. The proposed obfuscation technique protects from intruders. The proposed technique takes considerable minimum amount of time when compared with the existing method.","PeriodicalId":412668,"journal":{"name":"2019 International Conference on Issues and Challenges in Intelligent Computing Techniques (ICICT)","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":"{\"title\":\"Enhanced key establishment technique for secure data access in cloud\",\"authors\":\"Vidhisha Reddy, G. Prakash\",\"doi\":\"10.1109/ICICT46931.2019.8977720\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Today the IT environment concentrates on Cloud computing where the usage of cloud based applications poses various security threats. Many possible cloud applications fall victim to a tragedy of the generic approach such that a shared cloud service is becoming unstable and insecure based on the commercial demands by IT and other business organization. Companies should develop proper security guidelines for public and private cloud use and utilize an adequate cloud access model. Based on set of features in the three common cloud services, a set of security capabilities is identified which are needed to exercise those characteristic and the cryptographic dealing they entail. Random Number Generators can be used in cloud hosts especially for virtualized machines. Several purpose of Pseudo Random Number Generator (PRNG) exists in cloud which mainly can be used to authenticate users to the information stored on cloud, salts for the passwords or for statistical sampling. ANSI X9.31 is one standard pseudo random number generator used in many standard cryptographic algorithms like AES, RSA that are managed in securing data access in cloud applications. As ANSI X9.31 seed values are not secure they are directly used for generation. With brute force attack the seed values are exposed. On retrieval of seed values the key can be predicted which leads to insecurity of the information stored on the cloud. The proposed obfuscation technique protects from intruders. The proposed technique takes considerable minimum amount of time when compared with the existing method.\",\"PeriodicalId\":412668,\"journal\":{\"name\":\"2019 International Conference on Issues and Challenges in Intelligent Computing Techniques (ICICT)\",\"volume\":\"34 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"8\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 International Conference on Issues and Challenges in Intelligent Computing Techniques (ICICT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICICT46931.2019.8977720\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 International Conference on Issues and Challenges in Intelligent Computing Techniques (ICICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICT46931.2019.8977720","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

摘要

今天,IT环境集中在云计算上,使用基于云的应用程序会带来各种安全威胁。许多可能的云应用程序成为通用方法悲剧的受害者,例如,基于IT和其他业务组织的商业需求,共享云服务变得不稳定和不安全。公司应该为公共云和私有云的使用制定适当的安全指南,并利用适当的云访问模型。基于三种常见云服务中的一组特性,确定了一组安全功能,这些功能是执行这些特性和它们所带来的加密处理所需的。随机数生成器可以在云主机中使用,特别是用于虚拟机。伪随机数生成器(PRNG)存在于云中,主要用于对存储在云中信息的用户身份验证、密码生成或统计抽样。ANSI X9.31是许多标准加密算法(如AES、RSA)中使用的标准伪随机数生成器,这些算法用于保护云应用程序中的数据访问。由于ANSI X9.31种子值不安全,它们直接用于生成。暴力攻击会暴露种子值。在检索种子值时,可以预测密钥,从而导致存储在云上的信息不安全。提出的混淆技术可以防止入侵者。与现有方法相比,所提出的技术所需的时间相当少。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Enhanced key establishment technique for secure data access in cloud
Today the IT environment concentrates on Cloud computing where the usage of cloud based applications poses various security threats. Many possible cloud applications fall victim to a tragedy of the generic approach such that a shared cloud service is becoming unstable and insecure based on the commercial demands by IT and other business organization. Companies should develop proper security guidelines for public and private cloud use and utilize an adequate cloud access model. Based on set of features in the three common cloud services, a set of security capabilities is identified which are needed to exercise those characteristic and the cryptographic dealing they entail. Random Number Generators can be used in cloud hosts especially for virtualized machines. Several purpose of Pseudo Random Number Generator (PRNG) exists in cloud which mainly can be used to authenticate users to the information stored on cloud, salts for the passwords or for statistical sampling. ANSI X9.31 is one standard pseudo random number generator used in many standard cryptographic algorithms like AES, RSA that are managed in securing data access in cloud applications. As ANSI X9.31 seed values are not secure they are directly used for generation. With brute force attack the seed values are exposed. On retrieval of seed values the key can be predicted which leads to insecurity of the information stored on the cloud. The proposed obfuscation technique protects from intruders. The proposed technique takes considerable minimum amount of time when compared with the existing method.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信