Netinfo Security ›› 2019, Vol. 19 ›› Issue (6): 11-18.doi: 10.3969/j.issn.1671-1122.2019.06.002

Previous Articles     Next Articles

An Improved Scheme of Multi-PKG Cloud Storage Access Control

Zhongyuan QIN1(), Yin HAN1, Qunfang ZHANG2, Xuejin ZHU1   

  1. 1. School of Cyberspace Security, Southeast University, Nanjing Jiangsu 210096, China
    2. Artillery and Air-defence Institute Nanjing Campus, Nanjing Jiangsu 211132, China
  • Received:2019-02-27 Online:2019-06-10 Published:2020-05-11

Abstract:

In order to improve the security of cloud storage access control, an improved multiple private key generation center(PKG) cloud storage access control method based on attribute encryption is proposed. This paper first introduces the attribute encryption and access control model based on ciphertext-policy attribute-based encryption(CP-ABE). An improved multi-PKG scheme is then presented for cloud storage access control in this paper, which improves a single PKG to a primary PKG and several sub-PKGs. The primary PKG selects initialization parameters for generating a public key parameter and a master key of the primary PKG and each sub-PKG for data encryption. The sub-PKG then generates the relevant private key information and sends it to the client. Only the client receives the private key information of all the sub-PKGs to successfully calculate the private key for data decryption. This improved scheme can achieve flexible, fine-grained access control in the third-party server and the private key generation center(PKG) untrusted cloud storage scenario, while ensuring the confidentiality of user data. Ensure that for any ciphertext data stored by the user on the cloud server, only users who meet the corresponding attribute requirements can successfully decrypt to get the plaintext data, while any untrusted third party cannot illegally obtain the user’s private information independently.

Key words: attribute-based encryption, cloud storage, access control, multi-PKG

CLC Number: