期刊文献+

基于云雾计算的可追踪可撤销密文策略属性基加密方案 被引量:6

Traceable and revocable ciphertext-policy attribute-based encryption scheme based on cloud-fog computing
下载PDF
导出
摘要 针对资源受限的边缘设备在属性基加密中存在的解密工作开销较大,以及缺乏有效的用户追踪与撤销的问题,提出了一种支持云雾计算的可追踪可撤销的密文策略属性基加密(CP-ABE)方案。首先,通过对雾节点的引入,使得密文存储、外包解密等工作能够放在距离用户更近的雾节点进行,这样既有效地保护了用户的隐私数据,又减少了用户的计算开销;其次,针对属性基加密系统中用户权限变更、用户有意或无意地泄露自己密钥等行为,加入了用户的追踪和撤销功能;最后,通过算法追踪到做出上述行为的恶意用户身份后,将该用户加入撤销列表,从而取消该用户访问权限。性能分析表明,所提方案用户端的解密开销降低至一次乘法运算和一次指数运算,能够为用户节省大量带宽与解密时间,且该方案支持恶意用户的追踪与撤销。因此所提方案适用于云雾环境下计算资源受限设备的数据共享。 Focusing on the large decryption overhead of the resource limited edge devices and the lack of effective user tracking and revocation in attribute-based encryption,a traceable and revocable Ciphertext-Policy Attribute-Based Encryption(CP-ABE)scheme supporting cloud-fog computing was proposed.Firstly,through the introduction of fog nodes,the ciphertext storage and outsourcing decryption were able to be carried out on fog nodes near the users,which not only effectively protected users’private data,but also reduced users’computing overhead.Then,in response to the behaviors such as user permission changes,users intentionally or unintentionally leaking their own keys in the attribute-based encryption system,user tracking and revocation functions were added.Finally,after the identity of malicious user with the above behaviors was tracked through the algorithm,the user would be added to the revocation list,so that user’s access right was cancelled.The performance analysis shows that the decryption overhead at the user end is reduced to one multiplication and one exponential operation,which can save large bandwidth and decryption time for users;at the same time,the proposed scheme supports the tracking and revocation of malicious users.Therefore,the proposed scheme is suitable for data sharing of devices with limited computing resources in cloud-fog environment.
作者 陈家豪 殷新春 CHEN Jiahao;YIN Xinchun(College of Information Engineering,Yangzhou University,Yangzhou Jiangsu 225127,China;Guangling College of Yangzhou University,Yangzhou Jiangsu 225128,China)
出处 《计算机应用》 CSCD 北大核心 2021年第6期1611-1620,共10页 journal of Computer Applications
基金 国家自然科学基金资助项目(61472343)。
关键词 密文策略属性基加密 云计算 雾计算 外包解密 用户可追踪 用户可撤销 Ciphertext-Policy Attribute-Based Encryption(CP-ABE) cloud computing fog computing outsourcing decryption user traceable user revocable
  • 相关文献

参考文献4

二级参考文献37

  • 1Sahai A, Waters B. Fuzzy identity-based encryption. In: Cramer R, ed. Advances in Cryptology--EUROCRYPT 2005. Berlin: Springer-Verlag, 2005.457-473. [doi: 10.1007/11426639_27].
  • 2Goyal V, Pandey O, Sahai A, Waters B. Attribute-Based encryption for fine-grained access control of encrypted data. In: Proc. of the 13th ACM Conf. on Computer and Communications Security. New York: ACM Press, 2006. 89-98. [doi: 10.1145/1180405. 1180418].
  • 3Ostrovsky R, Sahai A, Waters B. Attribute-Based encryption with non-monotonic access structures. In: Proc. of the 14th ACM Conf. on Computer and Communications Security. New York: ACM Press, 2007. 195-203. [doi: 10.1145/1315245.1315270].
  • 4Attrapadung N, Imai H. Conjunctive broadcast and attribute-based encryption. In: Shacham H, Waters B, eds. Proc. of the Pairing-Based Cryptography--Pairing 2009. Berlin: Springer-Verlag, 2009.248-265. [doi: 10.1007/978-3-642-03298-1_16].
  • 5Attrapadung N, Imai H. Attribute-Based encryption supporting direct/indirect revocation modes. In: Parker MG, ed. Proc. of the Cryptography and Coding. Berlin: Springer-Verlag, 2009. 278-300. [doi: 10.1007/978-3-642-10868-6_17].
  • 6Bethencourt J, Sahai A, Waters B. Ciphertext-Poliey attribute-based encryption. In: Proc. of the 2007 IEEE Symp. on Security and Privacy. Washington: IEEE Computer Society, 2007. 321-334. http://ieeexplore.ieee.org/xpl/articleDetails.jsp?amumber=4223236 [doi: 10.1109/SP.2007.11].
  • 7Waters B. Ciphertext-Policy attribute-based encryption: An expressive, efficient, and provably secure realization. In: Catalano D, Catalano N, eds. Proc. of the Public Key Cryptography (PKC 2011). Berlin: Springer-Verlag, 2011. 53-70. [doi: 10.1007/978-3- 642-19379-8_4].
  • 8Su JS, Cao D, Wang XF, Sun YP, Hu QL. Attribute based encryption schemes. Journal of Software, 2011,22(6): 1299-1315 (in Chinese with English abstract), http://www.jos.org.cn/1000-9825/3993.htm [doi: 10.3724/SP.J.1001.2011.03993].
  • 9Hanaoka Y, Hanaoka G, Shikata J, Imai H. Identity-Based hierarchical strongly key-insulated encryption and its application. In: Roy B, cd. Advances in Cryptology--ASIACRYPT 2005. Berlin: Springer-Verlag, 2005. 495-514. Idol: 10.1007/11593447_27].
  • 10Boldyreva A, Goyal V, Kumar V. Identity-Based encryption with efficient revocation. In: Proc. of the 15th ACM Conf. on Computer and Communications Security. New York: ACM Press, 2008. 417-426. [doi: 10.1145/1455770.1455823].

共引文献58

同被引文献78

引证文献6

二级引证文献19

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部