Verified CSAC-Based CP-ABE Access Control of Cloud Storage in SWIM
Zhijun Wu, Jia Nie, Yue Yin, Hui Wang · 2021
As a wide-ranging distributed system, System Wide Information Management (SWIM) aims to provide an aviation information sharing platform that carries various information systems in the aviation field, so that the business of each subsystem can safely interact. As the data center of SWIM, the cloud storage platform has many functions and services based on third-party platforms. At the same time, it also brings the problem of a third-party trust crisis. In order to effectively verify the trustworthiness of third parties, this paper designs a new verifiable CSAC attribute encryption access control scheme. It introduces the cloud storage administration center (CSAC), and decentralizes multiple sub-authorization centers based on a subset of user attributes. The client uses the verification information provided by multiple sub-authorization centers to combine with the verification algorithm, which is based on the ciphertext access policy attribute encryption algorithm (CP-ABE) and introduces a secret sharing scheme that can identify fraudsters, and client can use this to verify CSAC. The credibility of and the security of key distribution. Compared with the previous solutions, this solution not only effectively solves the problem of the incomplete credibility of third parties, but also improves the efficiency of encryption and decryption, and ensures the security of data interaction in SWIM.