首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >Circuit Ciphertext-Policy Attribute-Based Hybrid Encryption with Verifiable Delegation in Cloud Computing
【24h】

Circuit Ciphertext-Policy Attribute-Based Hybrid Encryption with Verifiable Delegation in Cloud Computing

机译:云计算中具有可验证委托的基于电路密文策略属性的混合加密

获取原文
获取原文并翻译 | 示例

摘要

In the cloud, for achieving access control and keeping data confidential, the data owners could adopt attribute-based encryption to encrypt the stored data. Users with limited computing power are however more likely to delegate the mask of the decryption task to the cloud servers to reduce the computing cost. As a result, attribute-based encryption with delegation emerges. Still, there are caveats and questions remaining in the previous relevant works. For instance, during the delegation, the cloud servers could tamper or replace the delegated ciphertext and respond a forged computing result with malicious intent. They may also cheat the eligible users by responding them that they are ineligible for the purpose of cost saving. Furthermore, during the encryption, the access policies may not be flexible enough as well. Since policy for general circuits enables to achieve the strongest form of access control, a construction for realizing circuit ciphertext-policy attribute-based hybrid encryption with verifiable delegation has been considered in our work. In such a system, combined with verifiable computation and encrypt-then-mac mechanism, the data confidentiality, the fine-grained access control and the correctness of the delegated computing results are well guaranteed at the same time. Besides, our scheme achieves security against chosen-plaintext attacks under the -multilinear Decisional Diffie-Hellman assumption. Moreover, an extensive simulation campaign confirms the feasibility and efficiency of the proposed solution.
机译:在云中,为了实现访问控制并保持数据机密性,数据所有者可以采用基于属性的加密来加密存储的数据。但是,计算能力有限的用户更有可能将解密任务的掩码委派给云服务器,以降低计算成本。结果,出现了带有委派的基于属性的加密。尽管如此,在先前的相关工作中仍存在一些警告和问题。例如,在委派期间,云服务器可能会篡改或替换委派的密文,并以恶意意图响应伪造的计算结果。他们还可能通过使合格用户回避他们不符合成本节约的目的来欺骗他们。此外,在加密期间,访问策略也可能不够灵活。由于通用电路的策略能够实现最强大的访问控制形式,因此在我们的工作中已经考虑了一种实现具有可验证委托的基于电路密文策略的基于属性的混合加密的构造。在这样的系统中,结合可验证的计算和“先加密” mac机制,可以很好地同时保证数据的机密性,细粒度的访问控制和委托计算结果的正确性。此外,我们的方案在-multilinear Decision Diffie-Hellman假设下实现了针对选择明文攻击的安全性。此外,广泛的模拟活动证实了所提出解决方案的可行性和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号