信息网络安全 ›› 2019, Vol. 19 ›› Issue (10): 65-73.doi: 10.3969/j.issn.1671-1122.2019.10.009

• 技术研究 • 上一篇    下一篇

一种基于数据漂移的动态云安全存储机制

赵星1, 王晓东2, 张串绒3   

  1. 1.西安电子科技大学,陕西西安 710000
    2.厦门大学嘉庚学院,福建漳州 363105
    3.空军工程大学,陕西西安 710000
  • 收稿日期:2019-03-15 出版日期:2019-10-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:赵星(1980—),男,陕西,讲师,硕士,主要研究方向为信息安全;王晓东(1974—),男,陕西,副教授,博士,主要研究方向为电子通信工程、信息安全;张串绒(1965—),女,陕西,教授,博士,主要研究方向为密码学与网络安全。

  • 基金资助:
    国家自然科学基金面上项目[61272486/F020701]

A Dynamic Cloud Security Storage System Based on Data Drifting

Xing ZHAO1, Xiaodong WANG2, Chuanrong ZHANG3   

  1. 1. Xidian University, Xi’an Shannxi 710000, China;
    2.Tan Kah Kee College, Xiamen University, Zhangzhou Fujian 363105, China
    3. Air Force Engineering University, Xi’an Shannxi 710000, China;
  • Received:2019-03-15 Online:2019-10-10 Published:2020-05-11

摘要:

数据安全是云存储的基石,由于目前云存储系统数据存储物理位置相对固定,系统的不确定性和攻击复杂度均偏低。根据动态弹性安全防御的思想,通过动态改造,可以系统性地增加云存储的安全性。文章提出一种基于数据漂移技术的动态云安全存储机制,该存储机制首先将待存储文件分割成数据微粒并分散存储在不同的网络节点中;继而驱动数据微粒在存储节点间进行持续、随机化“漂移”;文件读取时就近聚集下载交付。为了提升系统的安全性,该存储机制的实现采用了均匀分布法与梅森旋转法组合的方法获得随机数;为了有效利用闲散网络带宽,同时不影响正常的网络数据通信,实现系统还增加了流量监控模块对数据的漂移进行主动控制。仿真表明,实验系统功能性及安全性良好。

关键词: 云存储, 安全, 动态, 漂移, 数据微粒

Abstract:

Data security is core issue of Cloud storage. Presently, Cloud storage physical positions of data are relatively changeless so that the uncertainty and complexity of system are low. According to the idea of dynamic resiliency for security defense, as long as the dynamic change is introduced, the security of Cloud storage might be enhanced systematically. Be derived from the idea, a novel mechanism, named dynamic cloud security storage system based on data drifting, is presented. The mechanism firstly separates a document into particles, and then stores them on different nodes of Cloud storage. The particles are driven to keep drifting among nodes during the store, to achieve the dynamic resilient storage view. Once user needs the document, all of the particles are gathered to the nearest node for following download. In order to improve the security, uniform distribution and Mason rotation method are mixed together to obtain better randomness. For the effective utilization of the idle network bandwidth, without affecting normal network data communication, the instance also adds a traffic monitoring module by actively drift traffic control. The simulations of the system with respect to the mechanism show that it has valid functions and security.

Key words: cloud storage, security, dynamic, drifting, data particle

中图分类号: