数据信封技术在云数据安全中的应用
ata Enveloping Techniques for Data Security in Cloud
云计算在提供高效、灵活服务的同时,存在着各种安全隐患。访问控制方法可以提高云端数据和资源的安全性,保护用户隐私,然而传统的访问控制方法需要较大的安全开销并且会产生大量数据冗余。本文通过资源分割技术对策略进行优化,并借助加密算法和粘性策略构建适用于云环境的安全数据信封。同时,建立资源与数据信封的映射关系,使得用户可以通过请求虚拟资源池,得到符合策略要求的资源。本文提出的决策方法改变了传统的遍历式规则,实现了用户请求的按需决策,提高了系统安全性和决策效率。最后,通过医疗隐私的案例阐述了方法的使用环境,并模拟仿真大量策略和规则验证算法效率。
loud computing are providing flexible and convenient services to satisfy the increasing demand of customers. However, the resources stored in the cloud may stay unsafe. Traditional access control methods bring up great security overhead and redundant of data. We optimize the policy on resource dimension, and construct cloud applicable data envelopes with the aid of encryption technique and sticky policy. At the same time, we map accessible resources to data envelopes, enabling users request to the virtual resource pool. The decision method proposed in this paper differs from traditional methods that traverse all rules for an explicit result, and it achieves the on-demand decision for user request, and improves the efficiency and security of the system. Finally, we present a case study of patient privacy preserving in healthcare, and simulate the decision-making through amount of synthetic policies.
虞慧群、裴新
计算技术、计算机技术安全科学
资源分割决策数据信封粘性策略云计算XACML
Resource segmentationdecision-makingdata envelopesticky policyXACMLcloud computing
虞慧群,裴新.数据信封技术在云数据安全中的应用[EB/OL].(2014-06-03)[2025-08-10].http://www.paper.edu.cn/releasepaper/content/201406-47.点此复制
评论