首页 | 本学科首页   官方微博 | 高级检索  
     

基于敏感等级的云租户数据安全保护模型研究
引用本文:江颉,顾祝燕,高俊骁,陈铁明. 基于敏感等级的云租户数据安全保护模型研究[J]. 系统工程理论与实践, 2014, 34(9): 2392-2401. DOI: 10.12011/1000-6788(2014)9-2392
作者姓名:江颉  顾祝燕  高俊骁  陈铁明
作者单位:浙江工业大学 计算机科学与技术学院, 杭州 310023
基金项目:国家自然科学基金(61103044);十二五国家密码发展基金(MMJJ201101009);浙江省自然科学基金(Y1110576);浙江省科技厅计划项目(2010C31126,2013C01121)
摘    要:为云计算提供有效的租户数据安全保护,提出一个第三方租户数据安全保护模型,解决租户数据的存储和检索安 全问题. 模型采用隐藏数据间关系的方法,对租户数据进行切片,利用单向函数混淆切片关系;结合租户对数 据的隐私需求和安全等级定义,给出租户数据的分级方法;依据安全等级对分割后的子表内容进行局部加密或匿名,实 现云端数据存储安全;结合私有信息检索技术,利用云端加密数据的关键字检索算法,隐藏租户搜索请求,保护云端数据 的检索安全. 实验表明,该模型能满足租户数据在未知云环境中的存储和检索安全要求.

关 键 词:云安全  等级保护  数据分割  私有信息检索  隐私保护  
收稿时间:2012-12-10

Cloud tenants-oriented data security protection model based on data sensitivity grading
JIANG Jie,GU Zhu-yan,GAO Jun-xiao,CHEN Tie-ming. Cloud tenants-oriented data security protection model based on data sensitivity grading[J]. Systems Engineering —Theory & Practice, 2014, 34(9): 2392-2401. DOI: 10.12011/1000-6788(2014)9-2392
Authors:JIANG Jie  GU Zhu-yan  GAO Jun-xiao  CHEN Tie-ming
Affiliation:College of Computer Science & Technology, Zhejiang University of Technology, Hangzhou 310023, China
Abstract:In order to provide effective security protection for tenants' data in cloud computing applications, a third-party security tenant's data protection model is proposed to solve the security problems of cloud tenants data storage and retrieval. Data relationship hiding method is conducted in this model, that is to say the tenants' data is firstly sliced and then one-way function is employed to confuse the relationship between these different data slices. According to the demand for data privacy as well as the security grade definition, a data security grading scheme is further proposed, and the data storage security can be guaranteed by utilizing some encryption and anonymization on the data in sub-tables segmented by the security grading scheme. Combining with private information retrieval method, a keyword retrieval algorithm on the encrypted data is also proposed to protect the cloud data demand privacy security from tenants. The experimental results show the proposed model can well meet the security requirements of tenants' data storage and retrieval in cloud.
Keywords:cloud security  security grade protection  data segmentation  private information retrieval  privacy preserving  
本文献已被 CNKI 等数据库收录!
点击此处可从《系统工程理论与实践》浏览原始摘要信息
点击此处可从《系统工程理论与实践》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号