• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2023, Vol. 45 ›› Issue (03): 434-442.

• 计算机网络与信息安全 • 上一篇    下一篇

基于密文强不可分性的云数据确定性删除方案

付伟1,谢振杰1,3,朱婷婷1,任正伟2   

  1. (1.海军工程大学信息安全系,湖北 武汉 430033;
    2.武汉科技大学计算机科学与技术学院,湖北 武汉 430081;3.中国人民解放军78156部队,重庆 400039)
  • 收稿日期:2022-06-06 修回日期:2022-09-06 接受日期:2023-03-25 出版日期:2023-03-25 发布日期:2023-03-22
  • 基金资助:
    国家自然科学基金(62276273)

An assured deletion scheme of cloud data based on strongly non-separable cipher

FU Wei1,XIE Zhen-jie1,3,ZHU Ting-ting1,REN Zheng-wei2   

  1. (1.Department of Information Security,Naval University of Engineering,Wuhan 430033;
    2.College of Computer Science & Technology,Wuhan University of Science and Technology,Wuhan 430081;
    3.Troop 78156 of PLA,Chongqing 400039,China)

  • Received:2022-06-06 Revised:2022-09-06 Accepted:2023-03-25 Online:2023-03-25 Published:2023-03-22

摘要: 实现云数据删除的确定性是云存储安全领域亟待解决的关键问题。现有方案普遍存在过度依赖于密钥销毁、不具备密文强不可分性和加解密开销过大等缺陷。结合AONT转换与分组加密,提出一种基于密文强不可分性的云数据确定性删除方案,通过混淆原始数据本身实现密文数据的强不可分性。理论分析和实验结果表明,该方案销毁密文数据的任何一个密文数据块都将导致原始数据无法复原,摆脱了对密钥销毁的过度依赖,实现了确定性删除的预期目标;通过引入数据块乱序并减少密码运算次数,在提升抗密文分析能力的同时大幅降低了计算开销,与现有方案相比具有明显的性能优势。

关键词: 云存储, 云安全, 确定性删除, 可信删除, 强不可分性, 数据销毁

Abstract: Assured deletion of cloud data is a key issue to be solved in the field of cloud storage secu- rity. Existing schemes generally have the drawbacks of over-reliance on key destruction, lack of strong non-separability of ciphertext, excessive encryption and decryption overhead and so on. To solve these problems, by combining AONT conversion with block cipher, a cloud data assured deletion scheme is proposed, which achieves strong non-separability of ciphertext by confusing the original data itself. Theoretical analysis and experimental results show that destroying any piece of cipher data will result in unrecoverable original data in this scheme, thus getting rid of over-reliance on key destruction, which achieves the expected goal of trusted deletion. At the same time, by introducing data block shuffling and reducing the number of cryptographic operations, the ability of anti-ciphertext analysis is improved and the computing overhead is significantly reduced. This scheme has obvious performance advantages compared with existing schemes.

Key words: cloud storage, cloud security, assured deletion, trusted deletion, strongly non-separable, data erasure