支持属性更新和撤销的文件安全共享方案

A FILE SECURITY SHARING SCHEME SUPPORTING EFFICIENT ATTRIBUTE UPDATE AND REVOCATION

  • 摘要: 属性基加密(Attribute-basedEncryption,ABE)方案多用于文件安全共享应用场景下的文件访问控制。如何实现用户属性动态变化下数据文件的高效安全共享是研究的热点问题之一。针对此问题,提出一种支持属性更新和撤销的属性基加密文件安全共享方案。该方案围绕文件安全共享问题,设计可实时撤销和动态更新用户属性的ABE方案。在密钥生成中心和用户之间使用安全的密钥分发协议,密钥生成中心无法计算完整的解密密钥,解决密钥托管问题。通过将加解密过程中的部分运算外包给代理服务器,用户只需一次指数运算就能获得明文。通过与已有方案的比较可知,该方案的加解密开销、私钥存储开销更低,且无须更新密文,具有更高的撤销效率。

     

    Abstract: Attribute-based encryption (ABE) is very suitable for file access control in multi-party file sharing application scenarios. Under the dynamic changed of user attributes, how to achieve efficient and secure sharing is one of the hot topics to be researched. To solve this problem, an attribute-based encryption file sharing scheme that supports attribute update and revocation is proposed. In this scheme, an ABE scheme that could revoke and dynamically update user attributes in real time was designed around the problem of file security sharing. A secure key distribution protocol was used between the key generation center and the user, the key generation center could not calculate the complete decryption key, and the key escrow problem was solved. By outsourcing part of the calculations in the encryption and decryption process to the proxy server, the user could obtain the plaintext with only one exponential operation. Compared with the existing schemes, it can be seen that the proposed scheme has lower encryption and decryption overhead and private key storage overhead, and does not need to update the ciphertext, and has higher revocation efficiency.

     

/

返回文章
返回