支持策略隐藏可撤销的无配对cp-abe数据共享方案
首发时间:2025-03-11
摘要:在物联网环境中部署基于密文策略的属性加密(ciphertext-policy attribute-based encryption, cp-abe)框架时,系统架构层面面临访问策略明文化存储引发的参与者敏感信息泄露的风险。一方面,现有策略隐藏方案中存在的加解密计算开销过大、用户属性表达能力受限等技术瓶颈;另一方面,当某个用户、某个属性过期之后,需要及时进行撤销以节省存储空间。对此,本文提出了一种基于椭圆曲线密码的支持策略隐藏可撤销cp-abe数据共享方案,通过属性列表实现相应属性撤销,借助线性秘密共享矩阵实现对访问策略的部分隐藏,并设计了一种在线隐私保护测试算法,通过边缘节点的分布式特性有效分担用户在数据存储与属性匹配测试过程中的额外开销,使方案更适配于物联终端。安全性分析与实验评估表明,所提方案在决定性diffie-hellman假设下可实现选择明文攻击下的不可区分性;在同样安全级别下,离线计算成本仅为一次标量乘运算,较同类算法在密文空间利用率上提升了50%~70%。
关键词:
for information in english, please click here
ecc-ph-maabe: ecc-based supporting policy hiding and attribute revocation cp-abe scheme
abstract:when deploying the ciphertext-policy attribute-based encryption (cp-abe) framework in internet of things (iot) environments, the system architecture faces the risk of leaking participants\' sensitive information due to the explicit storage of access policies. on the one hand, the existing policy hiding schemes have technical bottlenecks such as excessive encryption and decryption computation overheads and limited user attribute expression capabilities; on the other hand, when a user or an attribute has expired, it needs to be revoked in time to save storage space. in this paper, we propose an elliptic curve cryptography-based cp-abe data sharing scheme that supports policy hiding and revocable cp-abe data sharing, which achieves the revocation of the corresponding attributes through the attribute list, partially hides the access policy with the help of linear secret sharing scheme (lsss) matrix, and designs an online privacy testing algorithm, which can effectively share the extra costs of the users in the process of data storing and attribute matching testing through the distributed characteristics of edge nodes, so as to make the scheme more suitable for the users\' needs. the distributed nature of the edge nodes effectively shares the additional user overhead in the process of data storage and attribute matching test, which makes the scheme more suitable for iot terminals. the security analysis and experimental evaluation show that the proposed scheme can achieve indistinguishability under selective plaintext attack under the decisional diffie-hellman assumption (ddh) .under the same security level, the offline computation cost is only one scalar multiplication operation, which improves the ciphertext space utilisation by 50%~70% compared with similar algorithms.
keywords:
基金:
论文图表:
引用
导出参考文献
no.****
同行评议
勘误表
支持策略隐藏可撤销的无配对cp-abe数据共享方案
评论
全部评论