As data collection and analysis become critical functions for many cloud applications, proper data sharing with approved parties is required. However, the traditional data sharing scheme through centralized data escrow servers may sacrifice owners' privacy and is weak in security. Mainly, the servers physically own all data while the original data owners have only virtual ownership and lose actual access control. Therefore, we propose a 3-layer SSE-ABE-AES (3LSAA) cryptography-based privacy-protected data-sharing protocol based on the assumption that servers are honest-but-curious. The 3LSAA protocol realizes automatic access control management and convenient file search even if the server is not trustable. Besides achieving data self-sovereignty, our approach also improves system usability, eliminates the defects in the traditional SSE and ABE approaches, and provides a local AES key recovery method for user's availability.
翻译:随着数据收集和分析成为许多云层应用的关键功能,需要与经批准的各方适当共享数据,然而,通过中央数据代管服务器的传统数据共享计划可能牺牲所有者的隐私,而且安全性薄弱,主要是服务器实际拥有所有数据,而原始数据所有者只有虚拟所有权,失去实际访问控制,因此,我们基于服务器诚实但有争议的假设,提出了基于基于加密的基于加密的基于保密的保密数据共享协议。 3LSAA协议实现了自动访问控制管理和方便的文档搜索,即使服务器不可信。除了实现数据自上而下,我们的方法还提高了系统的可用性,消除了传统的SSE和ABE方法中的缺陷,并为用户的可用性提供了本地的AES关键回收方法。