...
首页> 外文期刊>Soft computing: A fusion of foundations, methodologies and applications >A decentralized multi-authority ciphertext-policy attribute-based encryption with mediated obfuscation
【24h】

A decentralized multi-authority ciphertext-policy attribute-based encryption with mediated obfuscation

机译:基于分散的多权力密文 - 策略属性的加密,介导混淆

获取原文
获取原文并翻译 | 示例
           

摘要

To ensure security and obtain fine-grained data access control policies in many management domains, multi-authority attribute-based encryption (MA-ABE) schemes were presented and have been applied in cloud storage system. There exist certain scenes where the application domains managed by different attribute authorities (AAs) often change, and hence domain managements require more autonomous and independent. However, most of existing schemes do not support flexible managements. In order to support dynamic managements, we propose a new decentralized ciphertext-policy MA-ABE scheme with mediated obfuscation (MA-DCP-ABE-WMO) where each of AAs works independently without any interaction with other AAs. When issuing a secret key to a user, each of AAs uses his secret to compute a share of the system master secret. Data are encrypted under the public keys of attribute management domains. To resist collusion attack, a common pseudorandom function PRF(center dot) is shared among AAs and is used to randomize each user's global identifier Gid. The randomized Gid is adopted to unify all target messages which need to be reconstructed from different management domains. We first introduce the mediated obfuscation (MO) model into MA-ABE scheme to provide online service and the interaction works among data owner, data user and the mediator. In the MO model, we define a special functional encryption scheme where the function program can be coded into an element of the multiplicative cyclic group. We obfuscate the function by randomly selecting a blinding factor to conduct exponent arithmetic with the base of the function. A special input of the function is constructed to cancel the blinding factor when calling the obfuscated function. It makes other participants know nothing about the inner function program but can evaluate the function program. Furthermore, the MA-DCP-ABE-WMO scheme is proved to be secure. Compared with related schemes, our scheme is suitable to dynamic domain managements. When the management domains are added or removed, the workload to update original ciphertexts and private keys is dramatically reduced.
机译:为确保在许多管理域中的安全性并获得细粒度的数据访问控制策略,提出了多个基于属性的加密(MA-ABE)方案,并已应用于云存储系统。存在某些场景,其中由不同属性当局(AAS)经常发生更改的应用程序域,因此域管理需要更自主和独立的。但是,大多数现有计划不支持灵活的管理。为了支持动态管理,我们提出了一种新的分散密文 - 政策MA-ABE方案,其中包括介导的混淆(MA-DCP-ABE-WMO),其中每个AAS独立工作,没有与其他AAS的任何互动。向用户发出秘密密钥时,每个AAS都使用他的秘密来计算系统主秘密的共享。数据在属性管理域的公钥下加密。为了抵抗勾结攻击,在AAS中共享一个常见的伪随机函数PRF(中心点),并用于随机化每个用户的全局标识符GID。采用随机GID统一从不同管理域重建的所有目标消息。我们首先将介导的混淆(MO)模型引入MA-ABE方案,以提供在线服务,并且数据所有者,数据用户和调解员之间的交互工作。在Mo模型中,我们定义了一种特殊的功能加密方案,其中功能程序可以被编码为乘法循环组的元素。我们通过随机选择致盲因子来对功能进行致盲因素来对指数算术与函数的基础进行控制。函数的特殊输入被构造成在调用混淆函数时取消致盲因子。它使其他参与者对内部功能计划一无所知,但可以评估功能程序。此外,证明了MA-DCP-ABE-WMO方案是安全的。与相关方案相比,我们的计划适合于动态域管理。添加或删除管理域时,要大大减少更新原始密文和私钥的工作负载。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号