支持属性撤销的多授权方完全适应性安全访问控制方案
网络出版日期: 2026-06-11
基金资助
国家自然科学基金(62471139,62072104,U21A20465);福建省科技兴警科研专项(2025YZ040003);福建省产业技术开发和应用计划项目(2025H0043)
版权
Multi-authority fully-adaptively secure access control scheme with attribute revocation
Online published: 2026-06-11
Copyright
多授权方属性基加密是多组织跨域协作场景下,实现数据安全访问控制的极具潜力的核心技术。然而,该类场景的动态特性易引发授权方适应性泄密风险,同时要求对用户部分属性与密钥进行定期更新。针对上述问题与挑战,本文提出一种支持属性撤销的多授权方完全适应性安全访问控制方案。该方案在保障完全适应性安全的前提下,通过设计专属撤销参数、构建高效的用户密钥更新算法,实现了多授权方场景下灵活、高效的属性撤销功能。为保障系统前后向安全,本文设计密文更新组件并提出轻量级密文更新方案,该方案仅需执行一次配对运算与一次乘法运算即可完成更新操作。安全性证明结果表明,该方案可满足完全适应性安全要求。本文通过理论分析与实验对比完成性能评估,测试结果表明,该方案在属性撤销阶段具有明显性能优势:密钥撤销计算开销仅为对比方案的25%,密文更新计算开销为常数级。
左雨庭 , 许力 , 李继国 , 田俊峰 . 支持属性撤销的多授权方完全适应性安全访问控制方案[J]. 网络空间安全科学学报, 2026 , 4(3) : 92 -104 . DOI: 10.20172/j.issn.2097-3136.260625
Multi-authority attribute-based encryption (MA-ABE) schemes serve as a promising core technology for secure data access control in multi-organizational cross-domain collaboration scenarios. However, the dynamic nature of such scenarios may cause adaptive leakage risks of authorities and require the periodic update of partial user attributes and secret keys. To address the above problems and challenges, this paper proposes a fully adaptive secure access control scheme supporting attribute revocation. While guaranteeing full adaptive security, the scheme designs dedicated revocation parameters and adopts an efficient user key update algorithm to realize flexible and efficient multi-authority attribute revocation. To guarantee forward and backward security, this paper constructs a ciphertext update component and proposes a lightweight ciphertext update mechanism, which only requires one pairing operation and one multiplication operation. Rigorous security proofs demonstrate that the proposed scheme satisfies full adaptive security. Theoretical analysis and experimental comparisons are performed for performance evaluation. The results show that the scheme achieves high efficiency in the attribute revocation phase. Specifically, the computational cost of key revocation is only 25% of that of comparable schemes, and the ciphertext update computational cost is at a constant level.
表 1 常用符号Table 1 Frequently used symbols |
| 符号 | 含义 |
| 双线性映射五元组 | |
| 授权集/属性集/属性全集 | |
| 固定/属性/撤销参数 | |
| Hash函数 | |
| 全局属性私钥 | |
| 数据请求者的属性密钥 | |
| 用于加密的数据及密文 | |
| 密文更新组件 | |
| 第k次更新后的密文 |
| 算法1 加密算法 |
| 输入:全局参数 输出:初始密文 1. 选择 2. 构造列向量 3. 构造列向量 4. for 5. 选择 6. 计算 7. 计算 8. 9. 计算 10. |
| 算法2 系统更新算法 |
| 输入:撤销参数 输出:更新后的撤销参数 1. 根据实际情况预设的安全阈值 2. for AAi 3. AAi 选择随机数 4. AAi 计算 5. for 6. AAi计算 7. if 超过 8. |
表 2 基本操作执行时长Table 2 Duration of basic operations |
| 群类型 | 运算类型 | 时间/ms |
| 四则运算 | 0.1 | |
| 指数 | 122 | |
| 配对操作 | — | 66 |
| 四则运算 | ||
| 指数 | 8 |
表 3 基础阶段的计算开销对比Table 3 Comparison of computing cost in the foundation phase |
| 方案 | 属性参数设置 | 密钥生成 | 加密 | 解密 |
| Datta等[17] | ||||
| Yang等[19] | ||||
| 本文 |
表 4 撤销阶段的计算开销对比Table 4 Comparison of computing cost in the revocation phase |
| 方案 | 系统更新 | 密钥更新 | 密文更新 |
| Yang等-1[19] | - | ||
| Yang等-2[19] | - | ||
| 本文 |
| 1 |
Zha D, Bhat Z P, Lai K H, et al. Data-centric artificial intelligence: a survey[J]. ACM Computing Surveys, 2025, 57 (5): 1- 42.
|
| 2 |
牛翔宇, 孔兰菊, 蒋亚丽, 等. 面向多层级区块链架构的轻量级高效验证资产跨链转移方法[J]. 计算机研究与发展, 2025, 62 (11): 2870- 2887.
Niu X Y, Kong L J, Jiang Y L, et al. A lightweight and efficiently verified assets cross-chain transfer method for multi-level blockchains architecture[J]. Journal of Computer Research and Development, 2025, 62 (11): 2870- 2887.
|
| 3 |
Nawrocki P, Osypanka P, Posluszny B. Data-driven adaptive prediction of cloud resource usage[J]. Journal of Grid Computing, 2023, 21 (1): 1- 19.
|
| 4 |
Farayola O A, Olorunfemi O L, Shoetan P O. Data privacy and security in it: a review of techniques and challenges[J]. Computer Science & IT Research Journal, 2024, 5 (3): 606- 615.
|
| 5 |
Zhang Y, Deng R, Xu S, et al. Attribute-based encryption for cloud computing access control: a survey[J]. ACM Computing Surveys (CSUR), 2020, 53 (4): 1- 41.
|
| 6 |
Wang X, Yu M, Wang Y, et al. Attribute-based access control encryption[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22 (3): 2227- 2242.
|
| 7 |
Ghopur D, Ma J, Ma X, et al. Puncturable ciphertext-policy attribute-based encryption scheme for efficient and flexible user revocation[J]. Science China Information Sciences, 2023, 66 (7): 172104.
|
| 8 |
Gu C, Li J, Zhang Y, et al. EABE-PUFPH: Efficient attribute-based encryption with reliable policy updating under full policy hiding[J]. IEEE Transactions on Computers, 2025, 74 (11): 3750- 3762.
|
| 9 |
苏泽林, 张文芳, 王小敏. 支持策略更新和即时密文验证的外包属性基加密方案[J]. 计算机研究与发展, 2024, 61 (12): 3088- 3097.
Su Z L, Zhang W F, Wang X M. Outsourced attribute-based encryption scheme with policy updating and verifiable ciphertext[J]. Journal of Computer Research and Development, 2024, 61 (12): 3088- 3097.
|
| 10 |
Sravya G, Kumar P S, Padmavathy R. Survey of post-quantum lattice-based ciphertext-policy attribute-based encryption schemes for cloud storage: taxonomy, open issues, and future directions[J]. IEEE Transactions on Services Computing, 2024, 17 (6): 4540- 4557.
|
| 11 |
周权, 卫凯俊, 陈民辉, 等. 基于区块链的国密轻量级属性基访问控制方案[J]. 密码学报, 2024, 11 (5): 1126- 1138.
Zhou Q, Wei K J, Chen M H, et al. Blockchain-based domestic cryptographic lightweight attribute-based access control scheme[J]. Journal of Cryptologic Research, 2024, 11 (5): 1126- 1138.
|
| 12 |
Chen L, Tai Z, Zhang H, et al. Traceable and revocable multi-authority attribute-based encryption with cloud and fog computing feasible for IoV[J]. IEEE Transactions on Dependable and Secure Computing, 2026.
|
| 13 |
Oberko P S, Obeng V H, Xiong H. A survey on multi-authority and decentralized attribute-based encryption[J]. Journal of Ambient Intelligence and Humanized Computing, 2022, 13 (1): 515- 533.
|
| 14 |
Duan P, Ma Z, Gao H, et al. Multi-authority attribute-based encryption scheme with access delegation for cross blockchain data sharing[J]. IEEE Transactions on Information Forensics and Security, 2024, 20, 323- 337.
|
| 15 |
Lin Y, Xiong H, Su H, et al. Multi-authority CP-ABE scheme with cryptographic reverse firewalls for internet of vehicles[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26 (4): 5348- 5359.
|
| 16 |
Lewko A, Waters B. Decentralizing attribute-based encryption[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Berlin, Heidelberg: Springer Berlin Heidelberg, 2011: 568-588.
|
| 17 |
Datta P, Komargodski I, Waters B. Fully adaptive decentralized multi-authority ABE[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham: Springer Nature Switzerland, 2023: 447-478.
|
| 18 |
Zuo Y, Xu L, Li J, et al. Secure and efficient blockchain-based access control scheme with attribute update[J]. IEEE Transactions on Consumer Electronics, 2025, 71 (1): 1539- 1550.
|
| 19 |
Yang F, Cui H, Jing J. Decentralized attribute-based access control with attribute revocation and outsourced decryption[C]//2023 15th International Conference on Computer Research and Development (ICCRD). IEEE, 2023: 246-257.
|
| 20 |
Chase M. Multi-authority attribute based encryption[C]//Theory of Cryptography: 4th Theory of Cryptography Conference, TCC 2007, Amsterdam, the Netherlands, Springer Berlin Heidelberg, 2007: 515-534.
|
| 21 |
Lin H, Cao Z, Liang X, et al. Secure threshold multi authority attribute based encryption without a central authority[J]. Information Sciences, 2010, 180 (13): 2618- 2632.
|
| 22 |
张学旺, 姚亚宁, 付佳丽, 等. 策略隐藏的高效多授权机构CP-ABE物联网数据共享方案[J]. 计算机研究与发展, 2023, 60 (10): 2193- 2202.
Zhang X W, Yao Y N, Fu J L, et al. Efficient multi-authority CP-ABE IoT data sharing scheme with hidden policies[J]. Journal of Computer Research and Development, 2023, 60 (10): 2193- 2202.
|
| 23 |
Waters B. Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization[C]//International Workshop on Public Key Cryptography. Berlin, Heidelberg: Springer Berlin Heidelberg, 2011: 53-70.
|
| 24 |
王静怡, 阚海斌. mHealth中细粒度策略隐藏和可追踪去中心访问控制方案[J]. 计算机研究与发展, 2024, 61 (6): 1525- 1535.
Wang J Y, Kan H B. Fine-grained policy-hiding and traceable decentralized access control scheme in mHealth[J]. Journal of Computer Research and Development, 2024, 61 (6): 1525- 1535.
|
| 25 |
Li W, Xue K, Xue Y, et al. TMACS: a robust and verifiable threshold multi-authority access control system in public cloud storage[J]. IEEE Transactions on Parallel and Distributed Systems, 2016, 27 (5): 1484- 1496.
|
| 26 |
Qin X, Huang Y, Yang Z, et al. A blockchain-based access control scheme with multiple attribute authorities for secure cloud data sharing[J]. Journal of Systems Architecture, 2021, 112, 101854.
|
| 27 |
Ambrona M, Gay R. Multi-authority ABE, revisited[J/OL]. Cryptology ePrint Archive, 2021. [2025-10-23] https://ia.cr/2021/1381.
|
| 28 |
Chen J, Chu Q, Gao Y, et al. Improved fully adaptive decentralized MA-ABE for NC1 from MDDH[C]//International conference on the Theory and Application of Cryptology and Information Security. Singapore: Springer Nature Singapore, 2023: 3-32.
|
| 29 |
Hur J, Noh D K. Attribute-based access control with efficient revocation in data outsourcing systems[J]. IEEE Transactions on Parallel and Distributed Systems, 2011, 22 (7): 1214- 1221.
|
| 30 |
王鹏翩, 冯登国, 张立武. 一种支持完全细粒度属性撤销的CP-ABE方案[J]. 软件学报, 2012, 23 (10): 2805- 2816.
Wang P P, Feng D G, Zhang L W. CP-ABE scheme supporting fully fine-grained attribute revocation[J]. Journal of Software, 2012, 23 (10): 2805- 2816.
|
| 31 |
Li J, Yao W, Han J, et al. User collusion avoidance CP-ABE with efficient attribute revocation for cloud storage[J]. IEEE Systems Journal, 2018, 12 (2): 1767- 1777.
|
| 32 |
肖浩, 徐子慧, 姜奇, 等. 面向工业物联网高效可撤销的属性基访问控制[J]. 网络空间安全科学学报, 2025, 3 (2): 84- 95.
Xiao H, Xu Z H, Jiang Q, et al. Efficient and revocable attribute-based access control for industrial internet of things[J]. Journal of Cybersecurity, 2025, 3 (2): 84- 95.
|
| 33 |
Yang K, Jia X, Ren K, et al. DAC-MACS: Effective data access control for multiauthority cloud storage systems[J]. IEEE Transactions on Information Forensics and Security, 2013, 8 (11): 1790- 1801.
|
| 34 |
Hong J, Xue K, Li W. Comments on “DAC-MACS: effective data access control for multiauthority cloud storage systems”/security analysis of attribute revocation in multiauthority data access control for cloud storage systems[J]. IEEE Transactions on Information Forensics and Security, 2015, 10 (6): 1315- 1317.
|
| 35 |
Tu S, Waqas M, Huang F, et al. A revocable and outsourced multi-authority attribute-based encryption scheme in fog computing[J]. Computer Networks, 2021, 195, 108196.
|
| 36 |
Liu Z, Jiang Z L, Wang X, et al. Practical attribute-based encryption: outsourcing decryption, attribute revocation and policy updating[J]. Journal of Network and Computer Applications, 2018, 108, 112- 123.
|
| 37 |
Decaro A, Iovino V. jPBC: Java pairing based cryptography[C]//2011 IEEE Symposium on Computers and Communications (ISCC). IEEE, 2011: 850-855.
|
| 38 |
Liu Z, Cao Z, Wong D S. Efficient generation of linear secret sharing scheme matrices from threshold access trees[DB/OL]. Cryptology ePrint Archive, 2010. [2025-10-23] https://ia.cr/2010/374.
|
/
| 〈 |
|
〉 |