作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2020, Vol. 46 ›› Issue (7): 150-158. doi: 10.19678/j.issn.1000-3428.0055413

• 网络空间安全 • 上一篇    下一篇


韩舒艳, 努尔买买提·黑力力   

  1. 新疆大学 数学与系统科学学院, 乌鲁木齐 830046
  • 收稿日期:2019-07-08 修回日期:2019-09-18 发布日期:2019-09-24
  • 作者简介:韩舒艳(1994-),女,硕士研究生,主研方向为密码学、信息安全;努尔买买提·黑力力(通信作者),教授、博士。
  • 基金资助:

CP-ABE Scheme Using Selectively Hidden Tree Access Structure

HAN Shuyan, Nurmamat Helil   

  1. College of Mathematics and System Science, Xinjiang University, Urumqi 830046, China
  • Received:2019-07-08 Revised:2019-09-18 Published:2019-09-24

摘要: 隐藏访问结构是密文策略属性基加密(CP-ABE)的安全操作,可有效防止敏感信息泄露,而现有树型访问结构的CP-ABE方案为完全公开或完全隐藏访问结构,造成策略保密性差及加解密计算量较大。为此,提出一种选择性隐藏树型访问结构的CP-ABE方案。使用互信息方法提取敏感属性特征,筛选和隐藏访问结构中含有原始属性集信息的部分属性,使选择隐藏与完全隐藏具有相同的保密效果。同时,以最少匹配代价判断用户解密能力,使无解密能力的用户尽早放弃解密。分析结果表明,与公开访问或完全隐藏访问结构方案相比,该方案的安全性更高且计算量更小。

关键词: 密文策略属性基加密, 属性提取, 选择性隐藏, 互信息, 属性匹配, 访问控制

Abstract: Hidden access structure is a secure operation of Ciphertext Policy Attribute Base Encryption(CP-ABE),which can effectively prevent the leakage of sensitive information.However,tree access structure used by existing CP-ABE schemes are either completely open or completely hidden,which results in poor policy confidentiality and a large amount of encryption and decryption computation.To address the problem,this paper proposes a CP-ABE scheme to selectively hide the tree access structure.The mutual information method is used to extract sensitive attribute features,filter and hide the attributes that contain the original attribute set information in the access structure,so that the selectively hidden structure has the same security as the fully hidden structure.At the same time,the decryption ability of users is judged at the lowest matching cost,so that the users without decryption ability give up decryption as early as possible.Analysis results show that compared with the schemes using open access or fully hidden access structure,the proposed scheme has higher security and less computation.

Key words: Ciphertext Policy Attribute Based Encryption(CP-ABE), attribute extraction, selectively hidden, mutual information, attribute matching, access control
