首页> 外文期刊>IEEE transactions on information forensics and security >Auditable $sigma $ -Time Outsourced Attribute-Based Encryption for Access Control in Cloud Computing
【24h】

Auditable $sigma $ -Time Outsourced Attribute-Based Encryption for Access Control in Cloud Computing

机译:可审核的$ sigma $-用于云计算中访问控制的时间外包基于属性的加密

获取原文
获取原文并翻译 | 示例
       

摘要

As a sophisticated mechanism for secure finegrained access control over encrypted data, ciphertext-policy attribute-based encryption (CP-ABE) is one of the highly promising candidates for cloud computing applications. However, there exist two main long-lasting open problems of CP-ABE that may limit its wide deployment in commercial applications. One is that decryption yields expensive pairing cost which often grows with the increase of access policy size. The other is that one is granted access privilege for unlimited times as long as his attribute set satisfies the access policy of a given ciphertext. Such powerful access rights, which are provided by CP-ABE, may be undesirable in real-world applications (e.g., pay-as-youuse). To address the above drawbacks, in this paper, we propose a new notion called auditable σ-time outsourced CF-ABE, which is believed to be applicable to cloud computing. In our notion, expensive pairing operation incurred by decryption is offloaded to cloud and meanwhile, the correctness of the operation can be audited efficiently. Moreover, the notion provides σ-time fine-grained access control. The cloud service provider may limit a particular set of users to enjoy access privilege for at most σ times within a specified period. As of independent interest, the notion also captures key-leakage resistance. The leakage of a user's decryption key does not help a malicious third party in decrypting the ciphertexts belonging to the user. We design a concrete construction (satisfying our notion) in the key encapsulation mechanism setting based on Rouselakis and Waters (prime order) CP-ABE, and further present security and extensive experimental analysis to highlight the scalability and efficiency of our construction.
机译:作为一种用于对加密数据进行安全细粒度访问控制的复杂机制,基于密文策略的基于属性的加密(CP-ABE)是云计算应用中极有希望的候选者之一。但是,CP-ABE存在两个主要的长期未解决的问题,可能会限制其在商业应用中的广泛部署。一个是解密产生昂贵的配对成本,配对成本通常随着访问策略大小的增加而增加。另一个是只要其属性集满足给定密文的访问策略,就可以无限次授予访问权限。 CP-ABE提供的这种强大的访问权限在实际应用中(例如,按使用付费)可能是不希望的。为了解决上述缺点,在本文中,我们提出了一种新的概念,称为可审计的σ时间外包CF-ABE,它被认为适用于云计算。在我们的概念中,解密产生的昂贵配对操作被转移到云中,同时,操作的正确性可以得到有效审核。而且,该概念提供了σ时间细粒度的访问控制。云服务提供商可能会限制特定用户组在指定时间段内最多最多σ次享受访问权限。作为独立利益,该概念还捕获了密钥泄漏抵抗。用户解密密钥的泄漏不会帮助恶意第三方解密属于该用户的密文。我们基于Rouselakis和Waters(主要顺序)CP-ABE在关键封装机制设置中设计了一个具体的结构(满足我们的想法),并进一步提供了安全性和广泛的实验分析,以突出我们结构的可伸缩性和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号