项目名称: 云计算安全中的密码新理论及关键技术研究
项目编号: No.61272486
项目类型: 面上项目
立项/批准年度: 2013
项目学科: 自动化技术、计算机技术
项目作者: 张串绒
作者单位: 中国人民解放军空军工程大学
项目金额: 79万元
中文摘要: 云计算作为极具优势的网络计算模式,其安全问题严重制约着它的广泛应用。本项目针对云计算数据安全、密钥管理等重要安全问题进行研究,拟从密码学角度给出解决问题的新理论和关键技术。首先,建立有可信第三方参与等典型安全需求下的云计算安全密码架构,并对这些架构的密码技术体系进行分析;其次,研究云计算数据安全、密钥管理等的关键密码技术和算法,给出高效可代理全同态加密和可公开验证门限秘密共享算法,提出可搜索签密并设计基于属性的可搜索签密算法;最后,对密码新理论及关键技术在云计算安全中的应用进行研究,分别设计不同密码架构下基于新全同态加密和可搜索签密的数据安全存储等协议,特别给出有可信第三方参与的密码架构下,基于新秘密共享的密钥分发、更新等密钥管理协议,并对协议性能进行仿真验证。本项目在理论和技术上的创新成果,将为云计算安全关键问题的解决提供重要理论和技术支持。因此,本项目的研究具有重要的理论和应用价值。
中文关键词: 云计算安全;格上同态加密;多秘密共享;安全多方计算;访问控制
英文摘要: Cloud computing, as a more powerful network computing model, is restrained from wide use for its security issues. This program aims to find out new cryptographic theory and key techniques with a strong focus on the study of the important security issues of data security and key management in cloud computing. First of all, cryptographic architectures of cloud computing security joined by the trusted third party, and other typical cases about security requirement are founded respectively; and then the cryptographic technical systems of these architectures are analyzed. Secondly, the key cryptographic technical and algorithms about data security and key management in cloud computing are studied. An efficient delegatable full homomorphic encryption algorithms and threshold secret sharing algorithms with public verifiability are given, as well as the searchable signcryption and its attribute-based algorithms are proposed. Finally, the application of the new theory and key techniques of cryptography in the security protocols of cloud computing are studied. The security data storage protocols and transmission protocols based on the new full homomorphic encryption and searchable signcryption are designed respectively; typically, under the cryptographic architecture joined by the trusted third party, the key management
英文关键词: cloud computing security;lattice-based homomorphic encryption;multi-secret sharing scheme;secure multi-party computation;access control scheme