用秘密共享实现文档密钥的安全存取,防泄漏还防篡改。
Access Control for Information-Theoretically Secure Key-Document Stores
- 基于谢尔文秘密共享,实现无条件安全的文档存取。
- 500,000文件中检索5,000关键词仅需231.5毫秒。
- 防止恶意用户和服务器泄露或篡改数据,适合高安全场景。
本文提出一种新型基于密钥的访问控制技术,用于安全外包键值存储系统,其中值为文档,通过密钥索引与访问。该方法采用谢尔文秘密共享,提供无条件或信息论安全性。支持基于关键词的文档检索,同时防止数据、用户访问权限或查询结果规模(即输出量)的泄露。所提方案可使服务器检测并终止恶意客户端的非法访问,防止恶意服务器未被察觉地篡改数据,且保证高效访问——在50万份文件中对5,000个关键词检索耗时仅231.5毫秒。
原文摘要 · Abstract (English)
This paper presents a novel key-based access control technique for secure outsourcing key-value stores where values correspond to documents that are indexed and accessed using keys. The proposed approach adopts Shamir's secret-sharing that offers unconditional or information-theoretic security. It supports keyword-based document retrieval while preventing leakage of the data, access rights of users, or the size (\textit{i}.\textit{e}., volume of the output that satisfies a query). The proposed approach allows servers to detect (and abort) malicious clients from gaining unauthorized access to data, and prevents malicious servers from altering data undetected while ensuring efficient access -- it takes 231.5ms over 5,000 keywords across 500,000 files.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。