首页> 外文会议>International symposium on cyberspace safety and security >Accountable Multi-authority Ciphertext-Policy Attribute-Based Encryption Without Key Escrow and Key Abuse
【24h】

Accountable Multi-authority Ciphertext-Policy Attribute-Based Encryption Without Key Escrow and Key Abuse

机译:基于负责人的多机构密文策略的基于属性的加密,无需密钥托管和密钥滥用

获取原文

摘要

Ciphertext-policy attribute-based encryption (CP-ABE) is a promising public key encryption primitive enabling fine-grained access control on shared data in public cloud. However, two quite challenging issues, the prevention of key escrow and key abuse, still exist in CP-ABE system. In this paper, we propose a multi-authority CP-ABE scheme without key escrow and key abuse. To prevent key escrow, multiple authorities are employed to perform the same procedure of key generation for an attribute. Thus, no individual authority or colluded authorities that manage no common attribute can decrypt any cipher-text, and it can also resist collusion attack from curious authority with the help of dishonest users. To prevent key abuse of dishonest users, user's global identifier along with a signature is embedded into the secret key. Thus, any third party can learn the identity from a shared secret key and publicly verify its validity. An advantage of simultaneously preventing key escrow and key abuse is that the proposed scheme can achieve accountability, i.e. an auditor can publicly audit a user or authorities abuse the secret key. At last, the proposed scheme is fully secure in the random oracle model, and due to a key aggregate algorithm its efficiency is comparable to the decentralizing CP-ABE scheme [18] on which it is based.
机译:基于密文策略的基于属性的加密(CP-ABE)是一种很有前途的公钥加密原语,可对公共云中的共享数据进行细粒度的访问控制。但是,CP-ABE系统中仍然存在两个具有挑战性的问题,即防止密钥托管和密钥滥用。在本文中,我们提出了一种没有密钥托管和密钥滥用的多权限CP-ABE方案。为了防止密钥托管,可以使用多个权限对属性执行相同的密钥生成过程。因此,没有一个管理公共属性的个人机构或合谋的机构不能解密任何密文,它也可以在不诚实的用户的帮助下抵御来自好奇的机构的合谋攻击。为了防止滥用不诚实用户的密钥,将用户的全局标识符和签名一起嵌入到秘密密钥中。因此,任何第三方都可以从共享密钥中学习身份,并公开验证其有效性。同时防止密钥托管和密钥滥用的优点是,所提出的方案可以实现问责制,即审计员可以公开审计用户或滥用密钥的机构。最后,所提出的方案在随机预言机模型中是完全安全的,并且由于采用了密钥聚合算法,其效率可与基于该方案的分散式CP-ABE方案[18]相提并论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号