跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.141) 您好!臺灣時間:2026/08/24 11:37
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:黃文欣
研究生(外文):Wen-Hsin Huang
論文名稱:雲端計算安全機制之研究
論文名稱(外文):A Research on Security Mechanisms for Cloud Computing
指導教授:張雅芬張雅芬引用關係
指導教授(外文):Ya-Fen Chang
學位類別:碩士
校院名稱:國立臺中科技大學
系所名稱:資訊工程系碩士班
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2018
畢業學年度:106
語文別:英文
論文頁數:34
中文關鍵詞:雲端計算驗證安全性生物特徵物聯網物聯雲資料協作資料機密性基於分層屬性的加密
外文關鍵詞:cloud computingauthenticationanonymitybiometricsthe Internet of Things (IoT)Cloud of Things (CoT)data collaborationdata confidentialityhierarchical attribute-based encryption
相關次數:
  • 被引用被引用:0
  • 點閱點閱:214
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
雲端計算是一種新興和應用廣泛的概念。透過雲端計算,軟體和硬體的資源及資訊可被共享,另外,它為企業提供了低成本的服務,並提高效率。雖然雲端計算帶給人們便利,為了確保數據的安全性和資料的隱私,雲端服務供應商必須將數據保護、身分管理、應用安全、隱私保護視為重點。
在本研究中,我們針對雲端計算的安全機制進行討論。首先,在2017年,Kumari等學者為了確保用戶與雲端伺服器之間的通訊安全以實現物聯雲,提出了一種基於生物特徵的認證方案,並宣稱他們的方法可確保用戶匿名性。在分析Kumari等學者的方法後,我們發現他們的方法存在一個缺失,它無法保證用戶匿名。
另一方面,使用者將共享的機密資料儲存在雲中,這使得資料安全成為一個重要的議題。為確保資料安全,雲服務提供商必須提供完善的安全機制,該安全機制須具備可靠的加密方法和合適的存取控制系統。為實現此理想,Huang等學者在2017年提出了一種基於分層屬性加密的資料協作方案。並宣稱他們的方法可以保證資料機密性。在分析了Huang等學者的方案之後,我們發現他們的方案存在一個弱點,即半可信的雲服務提供者可以解密受保護的數據以獲得機密資料。在這篇研究中,我們將明確指出Kumari等學者和Huang等學者針對雲端計算不同應用所提出方案所面臨之資訊安全威脅。
Cloud computing, a new and widely-applied concept, makes hardware, software and information shared. It provides low-cost services for business and improves efficiency. Although cloud computing brings people convenience, cloud service providers must focus on data protection, identity management, application security, and privacy to ensure that data is secure and data privacy is protected.
In this thesis, we make discussions on security mechanisms for cloud computing. In 2017, Kumari et al. proposed a biometrics-based authentication scheme to ensure the security of communications between a user and cloud-servers to realize Cloud of Things. They claimed their scheme ensured user anonymity. After analyzing Kumari et al.’s scheme, we find that one weakness exists in their scheme such that user anonymity is not ensured as claimed.
On the other hand, users store and share confidential data in the cloud while this approach makes data security become an important and tough issue. To ensure data security, cloud service providers must provide efficient and feasible mechanisms to provide a reliable encryption method and a suitable access control system. In order to realize this ideal, Huang et al. proposed a data collaboration scheme with hierarchical attribute-based encryption in 2017. After analyzing Huang et al.’s scheme, we find that one weakness exists in their scheme such that the semi-trusted cloud service provider can decrypt the protected data to obtain the plaintext. Data confidentiality is not ensured as claimed. In this thesis, we will explicitly indicate how these weaknesses damage Kumari et al.’s and Huang et al.’s schemes designed for different applications in cloud computing.
中文摘要 i
Abstract ii
誌 謝 iii
Table of contents iv
List of tables vi
List of figures vii
Chapter 1. Introduction 1
1.1 Motivation and background 1
1.2 Thesis organization 6
Chapter 2. Review of Kumari et al.’s scheme 7
2.1 Notations 7
2.2 Initialization and specification phase 8
2.3 Registration phase 8
2.4 Login phase 10
2.5 Authentication and key agreement phase 11
2.6 Password and biometrics change phase 12
Chapter 3. Analysis on Kumari et al.’s scheme 15
3.1 No user anonymity 15
3.2 Further discussions 17
Chapter 4. Review of Huang et al.’s scheme 18
4.1 Notations 18
4.2 Algorithms 19
4.3 System setup phase 20
4.4 Domain setup phase 20
4.5 Key generation phase 21
4.6 Data encryption phase 21
4.7 Data decryption phase 22
4.8 Data modification phase 24
Chapter 5. Analysis on Huang et al.’s scheme 28
5.1 Re-encrypting data with the same DK 28
5.2 Re-encrypting data with new DK by executing data encryption phase 29
Chapter 6. Conclusions 31
Bibliography 32
[1] Q. Huang, Z. Ma, Y. Yang, J. Fu and X. Niu, “Secure data sharing and retrieval using attribute-based encryption in cloud-based OSNs,” Chinese Journal of Electronics, Vol. 23, pp.557-563, 2014.

[2] C. Stergiou, K. E. Psannis, B. G. Kim and B. Gupta, “Secure integration of IoT and cloud computing,” Future Generation Computer Systems, Vol. 78 , pp. 964-975, 2018.

[3] E. Yoon and K. Yoo, “Robust biometrics-based multi-server authentication with key agreement scheme for smart cards on elliptic curve cryptosystem,” The Journal of Supercomputing, Vol. 63, No. 1, pp. 235-255, 2013.

[4] D. He and D. Wang, “Robust biometrics-based authentication scheme for multiserver environment,” IEEE Systems Journal, Vol. 9, No, 3, pp. 816-823, 2015.

[5] V. Odelu, A.K. Das and A. Goswami, “A secure biometrics-based multi-server authentication protocol using smart cards,” IEEE Transactions on Information Forensics and Security, Vol. 10, No. 9, pp. 1953-1966, 2015.

[6] M.C. Chuang and M.C. Chen, “An anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards and biometrics,” Expert Systems with Applications, Vol. 41, No. 4, pp. 1411-1418, 2014.

[7] D. Mishra, A.K. Das, and S. Mukhopadhyay, “A secure user anonymity-preserving biometric-based multi-server authenticated key agreement scheme using smart cards,” Expert Systems with Applications, Vol. 41, No. 18, pp. 8129-8143, 2014.

[8] H. Lin, F. Wen, and C. Du, “An improved anonymous multi-server authenticated key agreement scheme using smart cards and biometrics,” Wireless Personal Communications, Vol. 84, No. 4, pp. 2351-2362, 2015.

[9] Y. Lu, L. Li, H. Peng and Y. Yang, “A biometrics and smart cards-based authentication scheme for multi-server environments,” Security and Communication Networks, Vol. 8, No 17, pp. 3219-3228, 2015.

[10] S. Kumari, X. Li, F. Wu, A. K. Das and K. R. Choo, “Design of a provably secure biometrics-based multi-cloud-server authentication scheme,” Future Generation Computer Systems, Vol. 68, pp. 320-330, 2017.

[11] Y.F. Chang, W.H. Huang and W.L. Tai, “Comments on a provably secure biometrics-based multi-cloud-server authentication scheme,” Proceedings of IAM2018 Winter, pp. 103-112, 2018.

[12] S. Yu, C. Wang, K. Ren, and W. Lou, “Achieving secure, scalable, and fine-grained data access control in cloud computing,” Proceedings of IEEE INFOCOM 2010, pp. 1-9, 2010.

[13] Q. Huang, Z. Ma, Y. Yang, J. Fu and X. Niu, “EABDS: attribute-based secure data sharing with efficient revocation in cloud computing,” Chinese Journal of Electronics, Vol. 24, pp. 862-868, 2015.

[14] X. Dong, J. Yu, Y. Luo, Y. Chen, G. Xue and M. Li, “Achieving secure and efficient data collaboration in cloud computing,” Proceedings of IEEE/ACM 21st International Symposium on Quality of Service(IWQoS), pp. 195-200, 2013.

[15] J. Hur and D.K. Noh, “Attribute-based access control with efficient revocation in data outsourcing systems,” IEEE Transactions on Parallel and Distributed Systems, Vol. 22, pp. 1214-1221, 2011.

[16] Z. Wan, J. Liu and R.H. Deng, “HASBE: a hierarchical attribute-based solution for flexible and scalable access control in cloud computing,” IEEE Transactions on Information Forensics and Security, Vol. 7, pp. 743-754, 2012.

[17] M. Li, S. Yu, Y. Zheng, K. Ren and W. Lou, “Scalable and secure sharing of personal health records in cloud computing using attribute-based encryption,” IEEE Transactions on Parallel and Distributed Systems, Vol. 24, pp. 131-143, 2013.

[18] Q. Huang, Y. Yang and M. Shen, “Secure and efficient data collaboration with hierarchical attribute-based encryption in cloud computing,” Future Generation Computer Systems, Vol. 72, pp. 239-249, 2017.
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top
無相關期刊