首页> 外文期刊>Concurrency, practice and experience >Server-aided revocable attribute-based encryption for cloud computing services
【24h】

Server-aided revocable attribute-based encryption for cloud computing services

机译:基于服务器辅助的Revocable属性的云计算服务加密

获取原文
获取原文并翻译 | 示例
           

摘要

Attribute-based encryption (ABE) has been regarded as a promising solution in cloud computing services to enable scalable access control without compromising the security. Despite of the advantages, efficient user revocation has been a challenge in ABE. One suggestion for user revocation is using the binary tree in the key generation phase of an ABE scheme, which enables a trusted key generation center to periodically distribute the key update information to all nonrevoked users over a public channel. This revocation approach reduces the size of key updates from linear to logarithmic in the number of users. But it requires each user to keep a private key of the logarithmic size, and asks each nonrevoked user to periodically update his/her decryption key for each new time period. To further optimize user revocation in ABE, a server-aided revocable ABE (SR-ABE) scheme has been proposed, in which almost all workloads of users incurred by the user revocation are outsourced to an untrusted server, and each user only needs to store a private key of the constant size. In addition, SR-ABE does not require any secure channel for the key transmission, and a user only needs to perform a small amount of calculations to decrypt a ciphertext. In this paper, we revisit the notion of SR-ABE, and present a generic construction of SR-ABE, which can transform a revocable ABE (RABE) scheme to an SR-ABE scheme. In addition, we give an instantiation of SR-ABE by applying the generic construction on a concrete RABE scheme, and implement an instantiation of SR-ABE and an RABE scheme to evaluate the performance of SR-ABE.
机译:基于属性的加密(ABE)被视为云计算服务中有希望的解决方案,以便在不影响安全性的情况下实现可扩展的访问控制。尽管有了优势,但高效的用户撤销在ABE是一项挑战。用户撤销的一个建议是在ABE方案的密钥生成阶段中使用二进制树,这使得可信密钥生成中心能够通过公共信道周期性地将密钥更新信息分发到所有非删除用户。此撤销方法将键性的键更新的大小从位于用户的数量中降低到对数。但它要求每个用户保留对数大小的私钥,并询问每个非删除用户以定期更新每个新时间段的解密密钥。为了进一步优化ABE中的用户撤销,已经提出了一种服务器辅助Revocable APE(SR-ABE)方案,其中将用户撤销所产生的用户几乎所有的工作负载都将外包给不可信任的服务器,并且每个用户只需要存储常量尺寸的私钥。此外,SR-ABE不需要任何用于密钥传输的安全通道,并且用户只需要执行少量计算以解密密文。在本文中,我们重新审视了SR-ABE的概念,并提出了SR-ABE的通用构造,可以将可撤销的ABE(RABE)计划转变为SR-ABE计划。此外,我们通过在混凝土Rabe方案上应用通用结构,实施SR-ABE的实例化,并实施SR-ABE的实例化和Rabe计划,以评估SR-ABE的表现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号