Abstract:In order to solve the problems of password sniffing, replay attack and unauthorized operation in the current power payment terminal identity authentication and access control, in this paper a flexible data-access control scheme based on trust and reputation is proposed, which is applied to the power-terminal equipment data-access control in combination with cloud computing technology. The scheme controls the data access of the power terminal jointly by using attribute-based encryption and proxy re-encryption, the trust level evaluated by the terminal device and the user reputation generated by multiple reputation centers, and integrates the concept of user trust level and reputation evaluation into the encryption to support various control schemes and access strategies. Through the security and performance analysis of the proposed scheme, the fine-grained access control is proved, the data confidentiality is good, the communication overhead is flexible and controllable, the computational complexity is low, and the burden of the power terminal equipment is reduced.