...
首页> 外文期刊>Computers, Materials & Continua >An Efficient Ciphertext-Policy Attribute-Based Encryption Scheme with Policy Update
【24h】

An Efficient Ciphertext-Policy Attribute-Based Encryption Scheme with Policy Update

机译:具有策略更新的基于基于基于密文 - 策略的加密方案的基于策略的加密方案

获取原文
获取原文并翻译 | 示例
           

摘要

Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptographic solution to the problem for enforcing fine-grained access control over encrypted data in the cloud. However, when applying CP-ABE to data outsourcing scenarios, we have to address the challenging issue of policy updates because access control elements, such as users, attributes, and access rules may change frequently. In this paper, we propose a notion of access policy updatable ciphertext-policy attribute-based encryption (APU-CP-ABE) by combining the idea of ciphertext-policy attribute-based key encapsulation and symmetric proxy re-encryption. When an access policy update occurs, data owner is no longer required to download any data for re-encryption from the cloud, all he needs to do is generate a re-encryption key and produce a new encapsulated symmetric key, and then upload them to the cloud. The cloud server executes re-encryption without decryption. Because the re-encrypted ciphertext is encrypted under a completely new key, users cannot decrypt data even if they keep the old symmetric keys or parts of the previous ciphertext. We present an APU-CP-ABE construction based on Syalim et al.'s [Syalim, Nishide and Sakurai (2017)] improved symmetric proxy re-encryption scheme and Agrawal et al.'s [Agrawal and Chase (2017)] attribute-based message encryption scheme. It requires only 6 bilinear pairing operations for decryption, regardless of the number of attributes involved. This makes our construction particularly attractive when decryption is time-critical.
机译:基于密文 - 策略的基于策略的加密(CP-ABE)是一个有希望的加密解决方案,用于对云中的加密数据执行细粒度访问控制。但是,在将CP-ABE应用于数据外包方案时,我们必须解决策略更新的具有挑战性问题,因为访问控制元素(例如用户,属性和访问规则)可能经常更改。在本文中,我们通过组合基于密文 - 策略属性的密钥封装和对称代理重新加密的概念来提出基于访问策略可更新的密文 - 策略属性的访问(APU-CP-ABE)的概念。发生访问策略更新时,不再需要数据所有者来从云中下载任何数据进行重新加密,所有数据都需要生成重新加密密钥并生成新的封装对称密钥,然后将其上传到云端。云服务器在没有解密的情况下执行重新加密。由于重新加密的密文在完全新密钥下加密,因此即使它们保留旧对称键或先前密文的某些部分,用户也无法解密数据。我们提出了基于Syalim等人的APU-CP-ABE结构。's [Syalim,Nishide和Sakurai(2017)]改进了对称代理重新加密方案和Agrawal等人。的[Agrawal和Chase(2017)]属性基于邮件加密方案。无论所涉及的属性数量如何,它只需要6个双线性配对操作进行解密。这使得当解密是时间至关重要时,我们的建筑特别有吸引力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号