支持用户撤销的多授权机构的属性加密方案  被引量:2

Multi-authority and revocable attribute-based encryption scheme

在线阅读下载全文

作  者:李艳平[1] 齐艳姣 张凯[1] 魏旭光[1] LI Yah-ping;QI Yan-jiao;ZHANG Kai;WEI Xu-guang(School of Mathematics and Information Science,Shaanxi Normal University,Xi'an 710119,Shaanxi,China)

机构地区:[1]陕西师范大学数学与信息科学学院,陕西西安710119

出  处:《山东大学学报(理学版)》2018年第7期75-84,共10页Journal of Shandong University(Natural Science)

基  金:国家自然科学基金资助项目(61402275;61402015);陕西省自然科学基础研究计划资助项目(2016JM6069);中央高校基本科研业务费专项资金(GK201803005;GK201402004);人社部2015年留学人员科技活动项目

摘  要:目前多数基于属性加密的云存储访问控制研究是基于单授权机构,系统内仅有一个授权机构为用户颁发属性密钥,可信而好奇的单授权机构会凭借用户提交的属性对用户的身份、职业等隐私信息进行判断和推测,特别是在单授权机构不可信或遭受恶意攻击的情况下,可能造成密钥泄露而导致云端数据被非法解密。为了避免上述两种安全问题,结合现有的多授权机构的思想,使不同权限的授权机构管理不同属性并进行属性相关密钥分发,大大降低了单一信任机构的工作量,解决了单授权机构下的密钥泄露或滥用问题,同时提高了用户的隐私数据保护;通过访问树技术实现了AND、OR及Threshold灵活访问策略,且将用户身份标识设置在访问树中来实现用户的撤销,撤销出现后只需更新部分密文而无需更新属性密钥,因而减少了计算开销。在标准模型下证明了该方案在选择身份属性攻击模型下是安全的,其安全性规约到判定性双线性Diffie-Hellman(decisional bilinear Diffie-Hellman,DBDH)问题。Most of the existing attribute-based encryption schemes are based on a single authority. That is,there is only one authority in the system to issue the key to the user. The curious authority will speculate the user's identity,occupation and other private information by the user's attributes. In particular,if the single authority suffered malicious attacks,it maybe cause the leakage of private key and the breach of cloud data confidentiality. In order to avoid the above two kinds of problems,multi-authority is introduced in this paper. The different authorities manage different attributes and distribute the attributes key to users,which greatly decreases the single authority's workload,improves the protection of user privacy data and solves the key escrowunder a single or abuse authority. AND,OR and Threshold are flexible realized by using the access tree,and the user identity is set in the access tree to achieve the user's direct revocation. When the revocation occurs,the whole system only needs to update parts of the ciphertext without updating the attribute key,thus reducing the computational overhead of the cloud storage message. Finally,the proposed scheme is proved secure under the chosen identity attribute attack in the standard model,and the security of the scheme is built on the hardness assumption of decision bilinear Diffie-Hellman( DBDH) problem.

关 键 词:多授权机构 隐私保护 判定性双线性Diffie-Hellman问题 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象