Jul 2026· 2026 5th International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE)· pp. 1-8· 0 citations· 16 references
Abstract
The growing demand for large models in industrial Internet necessitates secure sharing of cloud-stored training data. However, existing Ciphertext-Policy Attribute-Based Encryption schemes suffer from low efficiency and insufficient accuracy in tracing key-leaking users. We propose a traceable secure data sharing scheme based on credibility, which enforces dual access control via credibility and attributes. It strengthens the binding of user and key and integrates a large model to create an intelligent traceability framework, utilizing multi-layer query mechanisms and Merkle trees to reduce redundant verification operations and improve tracing efficiency. Under the DBDH assumption, the scheme is IND-CPA secure. Experiments on the “Insider Threat Test Dataset” demonstrate a traceability accuracy of 99.46%, significantly reducing unnecessary verification operations. The proposed scheme provides an efficient, accurate, and practical solution for secure data sharing and malicious user traceability in distributed industrial cloud environments.
In cloud computing environments, data sharing serves as a foundational enabler of collaborative operations across heterogeneous terminals. However, such sharing introduces critical challenges–including privacy leakage, inadequate data security, inflexible access control policies, and substantial computational latency. To address these limitations, this paper proposes a privacy-preserving, secure data-sharing framework tailored for edge-cloud collaborative architectures. Relative to conventional approaches, the proposed framework delivers three principal advancements: (1) User Privacy Protection: We design a secure query-matching algorithm that protects plaintext query keywords during data access. The Cloud Server (CS) performs matching over encrypted trapdoors without directly learning the queried keywords. (2) Computational Efficiency Improvement: Edge Servers (ESs) perform outsourced ciphertext transformation using user-specific transformation keys. The terminal only performs a lightweight local operation to recover the resource. This approach minimizes the computational overhead on the terminal side while safeguarding user privacy, and effectively reduces the overhead associated with user joining and revocation within the same group. (3) Fine-Grained, Policy-Driven Access Control: A cryptographically enforced, attribute- and keyword-aware access control mechanism is implemented, supporting precise, context-sensitive authorization decisions via encrypted keyword search and semantic matching–thereby enhancing both the security posture and operational flexibility of data access control.
Qikun Zhang, Zheng Cai, Jinbo Feng et al.· Journal of King Saud Univers...· 0 citations
Addressing the limitations of existing encryption methods that rely on a single fixed key and struggle to accommodate the diverse access and secure storage demands of massive network cloud data, this paper proposes a secure storage method for massive network cloud data based on the CP-ABE algorithm. A data distribution strategy based on consistent hashing and dynamic weight adjustment is designed, deploying a multi-copy redundant storage network to achieve efficient storage and access. Access policies are formulated based on data attributes, and the CP-ABE algorithm enables precise matching between user attributes and policies, supporting fine-grained permission control. A hierarchical key management mechanism based on elliptic curves is implemented, combined with dynamic update policies, to ensure data security throughout its entire lifecycle. Experiments demonstrate: When data scale increases to 200GB, the encryption time of this method rises gradually. In terms of storage integrity and high-concurrency read/write performance, this method significantly outperforms the comparison methods. By deeply integrating attribute encryption with a dynamic storage architecture, this approach enhances system scalability and access control flexibility while ensuring security.
Dan Pan, Yuzhang Lin, Luxin Lin et al.· Digital Signal and Computer...· 0 citations
As the cloud computing and mass data sharing develop, data integrity and privacy has become an imperativeissue. Conventional remote data auditing techniques tend to reveal sensitive data or they have high computational cost.In order to overcome these shortcomings, the Fully Homomorphic Encryption enhanced Remote Method Invocation(FHEbRMI) mechanism that includes a combination of the Modified Least Squares (MLS) optimization model and theproposed cloud auditing security and efficiency are proposed in this paper. The suggested system provides an encrypteddata auditing system, which involves RMI-based communication, to enable the client, server, and third-party auditor toperform their verification functions remotely without the disclosure of the plaintext data. An actual execution of thesuggested structure is introduced, such as secure key generation, trapdoor-based dimensionality reduction, ciphertextmultiplication, and optimized homomorphic functions. Moreover, the RMI interface provides a smooth communicationamong the distributed nodes and increases the scalability and minimizes transmission delays. A comparative study withthe recent homomorphic-based auditing schemes like blockchain-assisted, certificateless and lattice-based FHE modelreveals that the proposed FHEbRMI-MLS model has better performance in terms of encryption/decryption latency,computational cost, and encryption overhead. The experimental performance is indicative of an average 37 and 42factor in speed of encryption and enhancement of computational efficiency respectively with respect to the traditionalFHE models. This paper presents a viable, privacy-friendly auditing framework of clouds which guarantees the end-toend encrypted verification without sacrificing the efficiency.
Deepshikha Chaturvedi, Vidyullata Devmane, Shashikant S. Radke et al.· International Journal of Com...· 0 citations
Multi-Key Searchable Encryption (MKSE) enables data owners (DOs) to outsource their data to a cloud server (CS) while supporting fine-grained data sharing with other authorized users. Most existing MKSE schemes can protect data users’ (DUs’) search query privacy against collusion attacks between malicious DOs and the CS. However, the CS is not fully trusted and may maliciously return forged or incomplete search results. To address this issue, Verifiable MKSE (VMKSE) is proposed by leveraging Garbled Bloom Filter (GBF), which can support verifiability even when the search results are empty. Unfortunately, due to the massive native storage redundancy of GBF, the storage and computational overhead of verification evidence generated in the sharing phase increases as the number of shared documents grows. Therefore, in this paper, we present a novel VMKSE scheme (VMKSE-BFF) by adopting BFF, which can simultaneously support verifiability of and secure data sharing in a multi-user setting. We provide a comparison with the existing VMKSE schemes. Experimental results on a real-world dataset show a significant performance improvement of VMKSE-BFF.
Yandong Su, Bing-Hang Wang, Yan-Jie Xiang et al.· Mathematics· 0 citations
A secure cloud computing scheme based on blockchain technology and DL based intrusion detection with the purpose to realize privacy-preserving cloud data management and may yield promising results in security cloud infrastructures for healthcare, and financial system as well as more intelligent enterprise(ies) in general.
Soujenya.voggu, Devarapu Shiva Prasad, Pasam Ramu et al.· International journal of com...· 0 citations
Federated learning enables collaborative model training between central servers and distributed clients without collecting users' raw sensitive data, which effectively promotes the large-scale deployment of intelligent collaborative services. Considering the high sensitivity of local training data and model gradient parameters in federated learning, protecting identity privacy and interaction security has become extremely critical. Therefore, mutual identity authentication is indispensable to restrict illegal client access and prevent malicious parameter transmission and data tampering. In this paper, we propose a lightweight anonymous authentication scheme for federated learning (FedLAS), which realizes secure mutual authentication between servers and clients and establishes a shared session key for subsequent encrypted interaction. In particular, the proposed scheme eliminates the reliance on high-cost cryptographic operations such as bilinear pairing, thus minimizing computational and communication overhead. Furthermore, informal security analysis demonstrates that our FedLAS scheme can resist multiple common attacks and meet predefined security requirements. Extensive comparative experiments show that the FedLAS scheme achieves excellent performance in computational and communication cost. It is well suitable for resource-constrained federated learning scenarios.
Shu Wu, Guoqiang Meng, Linlin Lu et al.· Scientific Reports· 0 citations