西安电子科技大学学报 ›› 2023, Vol. 50 ›› Issue (6): 195-206.doi: 10.19665/j.issn1001-2400.20230306

• 网络空间安全 • 上一篇    下一篇



  1. 1.南开大学 网络空间安全学院,天津 300350
    2.天津市网络与数据安全技术重点实验室,天津 300350
    3.中国科学院软件研究所,北京 100190
  • 收稿日期:2022-11-02 出版日期:2023-12-20 发布日期:2024-01-22
  • 通讯作者: 贾春福(1966—),男,教授,E-mail:cfjia@nankai.edu.cn
  • 作者简介:哈冠雄(1995—),男,南开大学博士研究生,E-mail:hgx1995@mail.nankai.edu.cn;|贾巧雯(1992—),女,中国科学院软件研究所博士研究生,E-mail:jiaqw@ios.ac.cn;|陈杭(1998—),女,南开大学硕士研究生,E-mail:2120200477@mail.nankai.edu.cn;|刘兰清(2000—),男,南开大学硕士研究生,E-mail:lqliu@mail.nankai.edu.cn
  • 基金资助:

Encrypted deduplication scheme with access control and key updates

HA Guanxiong1,2(),JIA Qiaowen3(),CHEN Hang1,2(),JIA Chunfu1,2(),LIU Lanqing1,2()   

  1. 1. College of Cyber Science,Nankai University,Tianjin 300350,China
    2. Tianjin Key Laboratory of Network and Data Security Technology,Tianjin 300350,China
    3. Institute of Software,Chinese Academy of Sciences,Beijing 100190,China
  • Received:2022-11-02 Online:2023-12-20 Published:2024-01-22



关键词: 云存储, 加密去重, 访问控制, 密钥更新, 可更新加密


In the scenario of data outsourcing,access control and key update have an important application value.However,it is hard for existing encrypted deduplication schemes to provide flexible and effective access control and key update for outsourcing user data.To solve this problem,an encrypted deduplication scheme with access control and key updates is proposed.First,an efficient access control scheme for encrypted deduplication is designed based on the ciphertext-policy attribute-based encryption and the proof of ownership.It combines access control with proof of ownership and can simultaneously detect whether a client has the correct access right and whole data content only through a round of interaction between the client and the cloud server,effectively preventing unauthorized access and ownership fraud attacks launched by adversaries.The scheme has features such as low computation overhead and few communication rounds.Second,by combining the design ideas of server-aided encryption and random convergent encryption,an updatable encryption scheme suitable for encrypted deduplication is designed.It is combined with the proposed access control scheme to achieve hierarchical and user-transparent key updates.The results of security analysis and performance evaluation show that the proposed scheme can provide confidentiality and integrity for outsourcing user data while achieving efficient data encryption,decryption,and key update.

Key words: cloud storage, encrypted deduplication, access control, key update, updatable encryption


  • TP309