首页 | 本学科首页   官方微博 | 高级检索  
     

云存储安全增强系统的设计与实现
引用本文:郝斐,王雷,荆继武,常建国.云存储安全增强系统的设计与实现[J].信息网络安全,2012(3):38-41.
作者姓名:郝斐  王雷  荆继武  常建国
作者单位:1. 中国科学院研究生院信息安全国家重点实验室,北京,100049;解放军北京军区总医院信息科,北京,100700
2. 中国科学院研究生院信息安全国家重点实验室,北京,100049
3. 解放军北京军区总医院信息科,北京,100700
摘    要:云存储是一种新型的网络存储形式,并逐步为大家所接受,企业和个人用户都开始使用云存储作为其网络存储媒介。目前很多著名的IT企业都推出了云存储服务,其中Amazon公司推出的SimpleStorageService(S3)就是商用云存储服务的典型代表。随着云存储的广泛使用,云存储中数据的安全问题,如数据泄漏和数据篡改,也成了用户广泛关注的问题。文章基于Amazons3的云存储服务,设计并实现了一款云存储安全增强系统,对用户上传至Amazons3的数据进行加密保护,使得文件以密文形式存储于Amazons3,可以有效防止数据在传输和存储过程中的泄漏;同时系统还对从s3下栽的文件进行完整性校验,检测其内容与上传时是否一致,以防止文件被篡改;最后,系统还提供了多用户访问控制支持,多个用户可以共享同一个S3账号,同时保证各自存储的内容互相隔离,禁止一个用户非授权访问其他用户存储的文件。

关 键 词:云存储  加解密  完整性校验  访问控制

The Design and Implementation of the Cloud Storage Based Security Enhancement System
HAO Fei , WANG Lei , JING Ji-wu , CHANG Jian-guo.The Design and Implementation of the Cloud Storage Based Security Enhancement System[J].Netinfo Security,2012(3):38-41.
Authors:HAO Fei  WANG Lei  JING Ji-wu  CHANG Jian-guo
Affiliation:2 ( 1. State Key Laboratory of Information Security, Graduate University of Chinese Academy of Sciences, Beijing, 100049, China; 2. Information Department, the Military General Hospital of Beijing PLA, Beijing, 100700, China )
Abstract:The cloud storage is a novel kind of network storage and is becoming more and more popular. Large quantities of enterprises and individual users adopt the cloud storage as their network storage mediums. So far, there are kinds of cloud storage service afforded by the famous IT enterprises, such as Simple Storage Service (S3), which is provided by Amazon. As the widespread use, the security issues of the cloud storage catch the eyes of researchers, such as data leakage and data tampering. In this paper, we proposed and implemented a security enhancement system, which is based on Amazon S3. The system is to protect users’ data through encrypting the plain texts before uploading them to Amazon S3, and when users want to download the texts, the system downloads and checks the integrity of the uploaded texts before decrypting and saving them on local file system. On this wise, we are capable of ensuring the data security while transmitting and storing, and guaranteeing the data integrity. What’s more, we proposed the fine-grained access control mechanism to achieve that many users are able to utilize the same Amazon S3 account while preserving the effective isolation of their files, and to prevent the unauthorized access to the uploaded files effectively.
Keywords:cloud storage  encipher and decipher  integrity check  access control
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号