基于可信硬件的隐私数据可搜索加密加速方法研究  被引量:5

Research on Acceleration Method of Searchable Encryption of Private Data Based on Trusted Hardware

在线阅读下载全文

作  者:杨光远 杨大利[1] 张羽[2] 马利民 张伟[1] Yang Guangyuan;Yang Dali;Zhang Yu;Ma Limin;Zhang Wei(School of Computer,Beijing Information Science&Technology University,Beijing 100101;Information and Network Security Department,National Information Center,Beijing 100045)

机构地区:[1]北京信息科技大学计算机学院,北京100101 [2]国家信息中心信息网络安全部,北京100045

出  处:《信息安全研究》2021年第4期319-327,共9页Journal of Information Security Research

基  金:国家自然科学基金面上项目(61872043)。

摘  要:可搜索加密(serachable encryption,SE)是构建加密数据库的关键技术之一,它允许服务器在不解密的情况下搜索加密数据.为了解决传统SE方案降低SE查询效率、增加客户端和服务器之间通信成本这2个问题,提出了采用硬件辅助解决方案(例如Intel SGX)来解决上述问题,关键思想是利用SGX来接管客户端跟踪关键字、添加数据、缓存删除的数据等任务.实验结果表明,通过在传统的可搜索加密方案中引入硬件辅助解决方案,有效地降低了客户端与不可信服务器之间的通信开销,并且提高了加密数据的查询性能.Searchable encryption (SE) is one of the key technologies for building encrypted databases.It allows the server to search for encrypted data without decrypting it.In order to solve the problems of advanced SE solution that it brings the lower efficiency of the SE query and increased the communication cost between the client and the server,a hardware-assisted solution(also known as Intel SGX)is proposed to alleviate the above bottleneck.The key idea is to use SGX to take over the client tasks such as tracking keywords,adding data,and caching deleted data.Experimental results show that the communication overhead between SGX and untrusted servers is effectively reduced,and the query performance of encrypted data is improved by introducing hardware-assisted solutions in the search process of encrypted data.

关 键 词:可搜索加密 可信执行环境 数据加密 数据安全 Intel SGX 

分 类 号:TP309.7[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象