首页> 外文期刊>World Wide Web >Sharing your privileges securely: a key-insulated attribute based proxy re-encryption scheme for IoT
【24h】

Sharing your privileges securely: a key-insulated attribute based proxy re-encryption scheme for IoT

机译:安全共享特权:基于密钥绝缘属性的IoT代理重新加密方案

获取原文
获取原文并翻译 | 示例
           

摘要

Attribute based proxy re-encryption (ABPRE) combines the merits of proxy re-encryption and attribute based encryption, which allows a delegator to re-encrypt the ciphertext according to the delegatees’ attributes. The theoretical foundations of ABPRE has been well studied, yet to date there are still issues in schemes of ABPRE, among which time-bounded security and key exposure protection for the re-encryption keys are the most concerning ones. Within the current ABPRE framework, the re-encryption keys are generated independently of the system time segments and the forward security protection is not guaranteed when the users’ access privileges are altered. In this paper, we present a key-insulated ABPRE scheme for IoT scenario. We realize secure and fine-grained data sharing by utilizing attribute based encryption over the encrypted data, as well as adopting key-insulation mechanism to provide forward security for re-encryption keys and private keys of users. In particular, the lifetime of the system is divided into several time slices, and when system enters into a new slice, the user’s private keys need are required to be refreshed. Therefore, the users’ access privileges in our system are time-bounded, and both re-encryption keys and private keys can be protected, which will enhance the security level during data re-encryption, especially in situations when key exposure or privilege alternation happens. Our scheme is proved to be secure under MDBDH hardness assumptions as well as against collusion attack. In addition, the public parameters do not have to be changed during the evolution of users’ private keys, which will require less computation resources brought by parameter synchronization in IoT.
机译:基于属性的代理重新加密(ABPRE)结合了代理重新加密和基于属性的加密的优点,这使委托者可以根据代表的属性对密文进行重新加密。已经对ABPRE的理论基础进行了充分的研究,但迄今为止,ABPRE方案中仍然存在一些问题,其中最受关注的是具有时间限制的安全性和用于重新加密密钥的密钥暴露保护。在当前的ABPRE框架内,重新加密密钥的生成与系统时间段无关,并且在更改用户的访问权限时不能保证前向安全保护。在本文中,我们针对物联网场景提出了一种密钥隔离的ABPRE方案。我们利用对加密数据进行基于属性的加密,并采用密钥隔离机制为用户的重新加密密钥和私钥提供前向安全性,从而实现安全,细粒度的数据共享。特别是,系统的生命周期分为几个时间片,当系统进入一个新的片时,需要刷新用户的私钥需求。因此,我们系统中用户的访问权限是有时间限制的,并且可以同时保护重新加密密钥和私钥,这将提高数据重新加密期间的安全级别,尤其是在发生密钥公开或特权更改的情况下。在MDBDH硬度假设下,我们的方案被证明是安全的,并且可以防止串通攻击。此外,在用户私钥的演变过程中不必更改公共参数,这将需要更少的物联网中参数同步带来的计算资源。

著录项

  • 来源
    《World Wide Web》 |2018年第3期|595-607|共13页
  • 作者

    Hanshu Hong; Zhixin Sun;

  • 作者单位

    Key Laboratory of Broadband Wireless Communication and Sensor Network Technology, Ministry Education, Nanjing University of Posts and Telecommunications;

    Key Laboratory of Broadband Wireless Communication and Sensor Network Technology, Ministry Education, Nanjing University of Posts and Telecommunications;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Attribute based encryption; Proxy re-encryption; Key exposure protection; Key insulation;

    机译:基于属性的加密;代理重新加密;密钥暴露保护;密钥隔离;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号