With the vigorous development of cloud storage services and the greater convenient of acquiring spatial and temporal information from mobile intelligent terminals, the objective of this project is to develop access control mechanisms for securely sharing resources and services across untrusted cloud providers. To achieve this goal, in this project we will explore effective mathematical representation of various spatial and temporal attributes, as well as secure computing algorithms on various range predicates. On this basis, we will design and implement cryptosystem with complex access control policy on spatial and temporal attributes and delegation mechanisms on encryption and decryption. Our proposed work includes the following two aspects: 1) Secure computing algorithms with multi-dimension policy enforcement on complex range predicates. We will investigate attribute-hidding predicate encryption supporting various integer comparison predicates by constructing order-preserving functions and homomorphic additions. Then, effective representations on multi-dimensional range predicates and secure computing algorithms will be implemented to develop the attribute-based encryption schemes with spatial and temporal constraints commonly required by fine-grained access control. 2) Delegation machanisms for temporal-spatial access control and secure retrieval over encrypted data. We will focus on encryption delegation for dynamic policy enforcement to support a variety of dynamic spatial and temporal attributes. Moreover, we will pursue attribute-hidding decryption delegation on range predicates to realize server-side verification of user's authentication levels on spatial-temporal attributes. The proposed work will provide a good theoretical and practical foundation for efficient and fine-grained access control in untrusted cloud environment. They will also lay a theoretical foundation for addressing some fundamental issues of access control in a variety of future network services.
鉴于云存储的蓬勃发展以及移动智能终端在获取时空信息的便利,本课题旨在研究面向云计算的安全数据与服务访控机制,通过探索数据加密中各类时空属性的数学表示方法与各种范围谓词的安全计算方法,设计并实现支持时间与空间上的复杂访控策略以及加密与解密委派机制的密码系统构建。研究内容包括:1)研究基于范围谓词的多维度时空访控技术,采用保序函数和加法同态,探索隐藏时空信息的安全比较算法,并研究支持多维度范围谓词的有效表示与算法实现方法,解决满足时空约束的基于属性加密构造;2)基于委派的时空访控和密文检索技术研究,研究基于加密委派的策略约束动态化问题,使其对各种时空动态属性予以支持,并探索面向范围谓词的解密委派,实现服务器端的时空属性策略授权验证方法。上述研究将为安全云计算构建和实现高效、细粒度的时空访控提供理论基础。
鉴于云存储的蓬勃发展以及移动智能终端在获取时空信息的便利,本课题旨在研究面向云计算的安全数据与服务访控机制,通过探索数据加密中各类时空属性的数学表示方法与各种范围谓词的安全计算方法,设计并实现支持时间与空间上的复杂访控策略以及加密与解密委派机制的密码系统构建。研究内容包括:1)研究基于范围谓词的多维度时空访控技术,采用保序函数和加法同态,探索隐藏时空信息的安全比较算法,并研究支持多维度范围谓词的有效表示与算法实现方法,解决满足时空约束的基于属性加密构造;2)基于委派的时空访控和密文检索技术研究,研究基于加密委派的策略约束动态化问题,使其对各种时空动态属性予以支持,并探索面向范围谓词的解密委派,实现服务器端的时空属性策略授权验证方法。上述研究将为安全云计算构建和实现高效、细粒度的时空访控提供理论基础。项目组共计发表学术论文40篇,申请专利9项,培养学生19名,所有指标超过预期1倍以上,圆满完成研究目标。
{{i.achievement_title}}
数据更新时间:2023-05-31
硬件木马:关键问题研究进展及新动向
端壁抽吸控制下攻角对压气机叶栅叶尖 泄漏流动的影响
青藏高原狮泉河-拉果错-永珠-嘉黎蛇绿混杂岩带时空结构与构造演化
面向云工作流安全的任务调度方法
基于ESO的DGVSCMG双框架伺服系统不匹配 扰动抑制
云端中支持细粒度访问控制策略的属性基加密
基于属性加密的数据访问控制方法研究
具有隐私保护的云数据安全计算和灵活访问控制关键技术研究
代码安全属性度量技术研究