吉林大学学报(信息科学版) ›› 2025, Vol. 43 ›› Issue (5): 1101-1110.

• • 上一篇    下一篇

基于 CP-ABE 结合非对称加密算法的云计算资源分级访问控制 

赵琳莹,王 超    

  1. 黄河交通学院智能工程学院,河南焦作454000
  • 收稿日期:2024-04-28 出版日期:2025-09-28 发布日期:2025-11-20
  • 作者简介:赵琳莹(1988— ), 女, 河南平顶山人, 黄河交通学院助教, 主要从事计算机技术研究, (Tel)86-15821866148(E-mail) zly25462023@163. com。
  • 基金资助:
    河南省高等学校重点科研基金资助项目(25B520042); 全国高等职业院校信息技术课程教学改革研究基金资助项目 (KT2024104); 黄河交通学院一流专业基金资助项目(HHJTXY-2023ylzy02); 黄河交通学院一流课程基金资助项目 (HHJTXY-2022ylkc45)

Hierarchical Access Control of Cloud Computing Resources Based on CP-ABE Combined with Asymmetric Encryption Algorithm 

ZHAO Linying, WANG Chao   

  1. School of Intelligent Engineering, Huanghe Jiaotong University, Jiaozuo 454000, China
  • Received:2024-04-28 Online:2025-09-28 Published:2025-11-20

摘要: 针对云计算环境中存在多租户、多级安全需求等复杂场景,现有访问控制策略难以满足不同用户和应用的需求,导致资源访问安全性较低, 且加解密时消耗时间较长的问题, 将密文策略的属性基加密(CP- ABE: Ciphertext-Policy Atlribute-Based Encryption)与非对称加密(RSA: Rivest-Shamir-Adleman)相结合, 对云计算资源分级访问控制进行了研究。 建立CP-ABE访问控制架构, 并制定加密访问策略。 在上述内容支持下, 利用云计算资源分级访问相关信任值明确访问信任关系, 获得访问主体与客体资源的信任度。 结合计算所得信任值对用户进行分级授权,以满足多租户、多级安全需求。 最后根据用户身份分级授权的结果,采用 RSA 算法替代CP-ABE复杂的双线性映射进行加解密, 实现资源分级访问精准控制, 降低加解密时间消耗。 实验测试结果表明,所提方法并发连接数可达400,分级访问过度授权率最大值为6.8%, 且访问控制响应时间可有效控制在6 s以内,能有效满足多租户、多级安全需求应用场景,具有较好的云计算资源分级访问控制效果。

关键词: 改进属性基加密, 云计算, 访问精准控制, 信任度, 分级授权

Abstract: Due to the complexity of multi tenant and multi-level security requirements in cloud computing environments, existing access control strategies are difficult to meet the needs of different users and applications, resulting in lower resource access security and more time consumption during encryption and decryption. To address the above issues, combining CP-ABE(Ciphertext Policy-Attribute Based Encryption) with asymmetric encryption RSA(Rivest Shamir Adleman) research on hierarchical access control of cloud computing resources is conducted. A CP-ABE access control architecture is established and encrypted access policies are developed. The trust values related to hierarchical access of cloud computing resources is used to clarify the trust relationship of access, and the trust degree of access subject and object resources are obtainined. Based on the calculated trust value, users are granted hierarchical authorization to meet the needs of multi tenant and multi-level security. Based on the results of user identity hierarchical authorization, the RSA algorithm is used to replace the complex bilinear mapping of CP-ABE for encryption and decryption, achieving precise control of resourcehierarchical access and reducing encryption and decryption time consumption. Through experimental testing, it was found that the proposed method can achieve a concurrent connection count of 400, a maximum over authorization rate of 6. 8% for hierarchical access, and an effective control of access control response time of less than 6 seconds, which can effectively meet the multi tenant and multi-level security needs of application scenarios. It has a good effect on hierarchical access control of cloud computing resources. 

Key words: improve attribute based encryption, cloud computing, access precise control, trust level, graded authorization

中图分类号: 

  • TP301.6