支持用户撤销的格基属性加密方案
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(U2336205,62202231,62202230,62302224,62302226);云南省重大科技专项计划(202302AD080002)
版权
User-revocable attribute based encryption scheme from lattices
Online published: 2025-01-25
Supported by
National Natural Science Foundation of China (U2336205, 62202231,62202230, 62302224,62302226);Yunnan Province Science and Technology Major Project (202302AD080002)
Copyright
针对适用于物联网(Internet of Things,IoT)设备中的用户权限动态管理,提出了一种新型的支持撤销的格基安全密文策略属性加密方案。方案通过权威机构更新时间向量,实现了用户的动态撤销功能。它采用线性秘密共享方案(Linear Secret Sharing Scheme,LSSS)来表达访问结构,保障复杂访问控制策略如“与门”“或门”和门限访问策略的实施,而且实现了部分访问策略的隐藏,有效增强了方案的灵活性和安全性。安全性评估显示,该方案能够在选择访问结构和选择明文攻击的情境下维持密文的不可区分性,即使在面对合谋攻击时也同样有效。对比分析表明,方案在存储性能上较优,且支持用户撤销功能,为物联网环境中的数据安全和访问控制提供了一种高效且安全的解决方案。
刘玉靓 , 马彦奇 , 刘媛 , 周永彬 . 支持用户撤销的格基属性加密方案[J]. 网络空间安全科学学报, 2024 , 2(5) : 78 -86 . DOI: 10.20172/j.issn.2097-3136.240507
A novel revocation-supported lattice-based attribute-based encryption (ABE) scheme was proposed to address the dynamic management of user permissions in Internet of Things (IoT) devices. The scheme implemented the user dynamic revocation function through an authority’s update time vector. It employed a linear secret sharing scheme (LSSS) to represent the access structure, ensuring the enforcement of complex access control policies such as AND, OR, and threshold access strategy. Additionally, it achieved partial concealment of access policies, significantly enhancing the scheme’s flexibility and security. Security evaluation demonstrats that the scheme can maintain ciphertext indistinguishability under both chosen-access structure and chosen-plaintext attacks, even in the presence of collusion attacks. Comparative analysis shows that the scheme outperforms in terms of storage efficiency and supports user revocation functionality, providing an effective and secure solution for data security and access control in IoT environments.
表 1 相关方案的比较Table 1 Comparison of related schemes |
| 方案 | 隐私保护 | 撤销 | 公钥长度 | 用户私钥长度 | 密文长度 |
| 文献[20] | 不支持 | 不支持 | |||
| 文献[18] | 支持 | 不支持 | |||
| 文献[17] | 不支持 | 支持 | |||
| 本文 | 支持 | 支持 | |||
| 注: | |||||
| 1 |
YANG Y, WU L, YIN G, et al. A survey on security and privacy issues in Internet-of-Things[J]. IEEE Internet of things Journal, 2017, 4 (5): 1250- 1258.
|
| 2 |
HE D, KUMAR N, WANG H, et al. A provably-secure cross-domain handshake scheme with symptoms-matching for mobile healthcare social network[J]. IEEE Transactions on Dependable and Secure Computing, 2016, 15 (4): 633- 645.
|
| 3 |
SAHAI A,WATERS B. Fuzzy identity-based encryption[C]//Advances in Cryptology-EUROCRYPT 2005:24th Annual International Conference on the Theory and Applications of Cryptographic Techniques. Berlin,Heidelberg:Springer,2005:457-473.
|
| 4 |
MA H, PENG T, LIU Z. Directly revocable and verifiable key-policy attribute-based encryption for large universe[J]. International Journal of Network Security, 2017, 19 (2): 272- 284.
|
| 5 |
CHUNG P S, LIU C W, HWANG M S. A study of attribute-based proxy re-encryption scheme in cloud environments[J]. International Journal of Network Security, 2014, 16 (1): 1- 13.
|
| 6 |
SHI Y F, ZHENG Q J, LIU J Q, et al. Directly revocable key-policy attribute-based encryption with verifiable ciphertext delegation[J]. Information Sciences, 2015, 295, 221- 231.
|
| 7 |
HUR J, NOH D K. Attribute-based access control with efficient revocation in data outsourcing systems[J]. IEEE Transactions on Parallel and Distributed Systems, 2010, 22 (7): 1214- 1221.
|
| 8 |
HOANG V H,LEHTIHET E,GHAMRI-DOUDANE Y. Forward-secure data outsourcing based on revocable attribute-based encryption[C]//2019 15th International Wireless Communications & Mobile Computing Conference (IWCMC). IEEE,2019:1839-1846.
|
| 9 |
XU S, YANG G, MU Y. Revocable attribute-based encryption with decryption key exposure resistance and ciphertext delegation[J]. Information Sciences, 2019, 479, 116- 134.
|
| 10 |
FAN C I, HUANG V S M, RUAN H M. Arbitrary-state attribute-based encryption with dynamic membership[J]. IEEE Transactions on Computers, 2013, 63 (8): 1951- 1961.
|
| 11 |
LIU Z, DUAN S, ZHOU P, et al. Traceable-then-revocable ciphertext-policy attribute-based encryption scheme[J]. Future Generation Computer Systems, 2019, 93, 903- 913.
|
| 12 |
WANG S, GUO K, ZHANG Y. Traceable ciphertext-policy attribute-based encryption scheme with attribute level user revocation for cloud storage[J]. PLoS One, 2018, 13 (9): e0203225.
|
| 13 |
LAI J,DENG R H,LI Y. Expressive CP-ABE with partially hidden access structures[C]//Proceedings of the 7th ACM Symposium on Information,Computer and Communications Security. ACM,2012:18-19.
|
| 14 |
ZHANG Y, ZHENG D, DENG R H. Security and privacy in smart health: efficient policy-hiding attribute-based access control[J]. IEEE Internet of Things Journal, 2018, 5 (3): 2130- 2145.
|
| 15 |
YANG Y, SUN J, LIU Z, et al. Practical revocable and multi-authority CP-ABE scheme from RLWE for cloud computing[J]. Journal of Information Security and Applications, 2022, 65, 103108.
|
| 16 |
ZHAO S, JIANG R, Bhargava B. RL-ABE: a revocable lattice attribute based encryption scheme based on R-LWE problem in cloud storage[J]. IEEE Transactions on Services Computing, 2020, 15 (2): 1026- 1035.
|
| 17 |
于金霞, 杨超超, 张棋超, 等. 外包环境下格上可撤销的属性基加密方案[J]. 计算机科学与探索, 2020, 14 (2): 244- 251.
YU J X, YANG C C, ZHANG Q C, et al. Revocable ciphertext-policy attribute-based encryption in data outsourcing systems from lattices[J]. Journal of Frontiers of Computer Science and Technology, 2020, 14 (2): 244- 251.
|
| 18 |
LIU Y, WANG L, SHEN X, et al. Space-efficient key-policy attribute-based encryption from lattices and two-dimensional attributes[J]. Security and Communication Networks, 2020, (1): 2345369.
|
| 19 |
MICCIANCIO D,PEIKERT C. Trapdoors for lattices:simpler,tighter,faster,smaller[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Berlin,Heidelberg:Springer,2012:700-718.
|
| 20 |
GUR K D, POLYAKOV Y, ROHLOFF K, et al. Practical applications of improved gaussian sampling for trapdoor lattices[J]. IEEE Transactions on Computers, 2018, 68 (4): 570- 584.
|
/
| 〈 |
|
〉 |