...
首页> 外文期刊>Information Sciences: An International Journal >(Dual) server-aided revocable attribute-based encryption with decryption key exposure resistance
【24h】

(Dual) server-aided revocable attribute-based encryption with decryption key exposure resistance

机译:(双)服务器辅助可撤销属性的加密,具有解密密钥曝光电阻

获取原文
获取原文并翻译 | 示例
           

摘要

Attribute-based encryption (ABE) is a promising approach that enables scalable access control on encrypted data. However, one of the main efficiency drawbacks of ABE is the lack of practical user revocation mechanisms. In ESORICS 2016, Cui et al. proposed the first cloud server-aided revocable ABE scheme to achieve efficient user revocation. However, the cloud server cannot be fully compromised by an adversary. Otherwise, it will suffer from local decryption key exposure (DKE) attacks. In this paper, we first revisit Cui et al. security model, and enhance it by capturing the DKE attacks on user's local decryption keys and meanwhile allowing the adversary to fully corrupt the cloud server. We then construct a server-aided revocable ABE based on Rouselakis-Waters ciphertext-policy ABE (CCS 2013). It was showed that our scheme is secure in the new security model and maintains the outstanding properties of efficient user revocation, short local ciphertext size and fast local decryption. Further, we propose a dual framework for server-aided revocable ABE, in which the update keys are distributed to local users rather than the cloud server. With the exception of interaction with the KGC, the local user still has the same efficiency as that of first scheme. (C) 2019 Elsevier Inc. All rights reserved.
机译:基于属性的加密(ABE)是一种有希望的方法,可在加密数据上实现可扩展的访问控制。然而,ABE的主要效率缺点之一是缺乏实用的用户撤销机制。在2016年的esorics 2016中,Cui等人。提出了第一个云服务器辅助可撤销APE方案,以实现有效的用户撤销。但是,云服务器不能被对手完全妥协。否则,它将遭受本地解密密钥曝光(DKE)攻击。在本文中,我们首先重新审视Cui等人。安全模型,并通过捕获用户本地解密密钥的DKE攻击来增强它,同时允许对手完全破坏云服务器。然后,我们根据RouseLakis-Waters密文 - 策略abe构建一个服务器辅助revocable abe(CCS 2013)。结果表明,我们的计划在新的安全模型中是安全的,并保持高效用户撤销,本地密文大小和快速本地解密的出色属性。此外,我们向服务器辅助Revocable ABE提出了一种双重框架,其中更新密钥分发给本地用户而不是云服务器。除了与KGC的互动之外,本地用户仍然具有与第一个方案相同的效率。 (c)2019 Elsevier Inc.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号