【24h】

Attribute Based Data Sharing with Attribute Revocation

机译:具有属性吊销的基于属性的数据共享

获取原文
获取原文并翻译 | 示例

摘要

Ciphertext-Policy Attribute Based Encryption (CP-ABE) is a promising cryptographic primitive for fine-grained access control of shared data. In CP-ABE, each user is associated with a set of attributes and data are encrypted with access structures on attributes. A user is able to decrypt a ciphertext if and only if his attributes satisfy the ciphertext access structure. Beside this basic property, practical applications usually have other requirements. In this paper we focus on an important issue of attribute revocation which is cumbersome for CP-ABE schemes. In particular, we resolve this challenging issue by considering more practical scenarios in which semi-trustable on-line proxy servers are available. As compared to existing schemes, our proposed solution enables the authority to revoke user attributes with minimal effort. We achieve this by uniquely integrating the technique of proxy re-encryption with CP-ABE, and enable the authority to delegate most of laborious tasks to proxy servers. Formal analysis shows that our proposed scheme is provably secure against chosen ciphertext attacks. In addition, we show that our technique can also be applicable to the Key-Policy Attribute Based Encryption (KP-ABE) counterpart.
机译:基于密文策略的基于属性的加密(CP-ABE)是一种有前途的加密原语,用于对共享数据进行细粒度的访问控制。在CP-ABE中,每个用户都与一组属性关联,并且使用属性上的访问结构对数据进行加密。仅当用户的属性满足密文访问结构时,用户才能解密密文。除了这个基本属性,实际应用通常还有其他要求。在本文中,我们专注于属性撤销的一个重要问题,这对于CP-ABE方案是很麻烦的。尤其是,我们通过考虑更实用的方案来解决此挑战性问题,在这些方案中可以使用半信任的在线代理服务器。与现有方案相比,我们提出的解决方案使机构能够以最小的努力撤销用户属性。我们通过将代理重新加密技术与CP-ABE进行独特的集成来实现这一目标,并使授权机构能够将大多数繁琐的任务委派给代理服务器。形式分析表明,我们提出的方案可证明对所选密文攻击的安全性。此外,我们证明了我们的技术还可以应用于基于密钥策略属性的加密(KP-ABE)对应项。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号