Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering

Previous Articles     Next Articles

Proxy-based Immediate Attribute Revocation KP-ABE Scheme

LIN Juan,XUE Qing-shui,CAO Zhen-fu   

  1. (Department of Computer Science and Engineering,Shanghai Jiaotong University,Shanghai 200240,China)
  • Received:2013-10-30 Online:2014-10-15 Published:2014-10-13

基于代理的即时属性撤销KP-ABE 方案

林 娟,薛庆水,曹珍富   

  1. (上海交通大学计算机科学与工程系,上海200240)
  • 作者简介:林 娟(1980 - ),女,硕士研究生,主研方向:密码学,信息安全;薛庆水,副教授、博士;曹珍富,教授、博士、博士生导师。
  • 基金资助:

    国家“973”计划基金资助项目(2012CB723401);国家自然科学基金资助项目(61170227,61161140320)。

Abstract:

Attribute revocation is crucial to the practical use of Attribute-based Encryption(ABE). Most of the existing revocable ABE schemes under the indirect revocation model suffer in terms of delaying in revocation or updating keys and ciphertexts. To address this,this paper proposes a proxy-based immediate attribute revocation Key Policy(KP) attributebased encryption under the indirect model without issuing new keys or re-encrypting existing ciphertexts. It achieves attribute revocation by introducing a proxy in the decryption process and reduces the burden for the key authority. The proxy is semi-trusted which revokes user access privileges and cannot decrypt ciphertexts. Analysis results show that the scheme supports fine-grained access control policies and achieves three kinds of revocation including system attribute revocation,user revocation and user attribute revocation.

Key words: Attribute-based Encryption ( ABE ), Key Policy ( KP ), access control, semi-trusted proxy, attribute revocation, immediate revocation

摘要:

属性撤销是属性基加密方案在实际应用中亟须解决的问题,已有支持间接撤销模式的可撤销属性基加密 方案存在撤销延时或需要更新密钥及密文等问题。为此,提出一种间接模式下基于代理的支持属性即时撤销的密 钥策略属性基加密方案,该方案不需要用户更新密钥及重加密密文,通过在解密过程中引入代理实现撤销管理,减 轻了授权机构的工作量,其要求代理为半可信,不支持为撤销用户提供访问权限及解密密文。分析结果表明,该方 案支持细粒度访问控制策略,并且可以实现系统属性的撤销、用户的撤销及用户的部分属性撤销。

关键词: 属性基加密, 密钥策略, 访问控制, 半可信代理, 属性撤销, 即时撤销

CLC Number: