可验证秘密共享
计算机科学
方案(数学)
计算机安全
延展性
密文
密文不可分辨性
计算机网络
加密
理论计算机科学
数学
程序设计语言
集合(抽象数据类型)
数学分析
作者
Zhishuo Zhang,Wen Huang,Lin Yang,Yongjian Liao,Shijie Zhou
标识
DOI:10.1109/jiot.2023.3268699
摘要
Outsourced decryption attribute-based encryption (OD-ABE) is emerging as a promising cryptographic tool to provide efficient fine-grained access control for data accessing and sharing in cloud-assisted Intelligent Internet of Mobile Things (IIoMT). Decryption verification is an essential property of OD-ABE to enable the mobile user to verify the precision of the decryption data. Unfortunately, the most representative verification (commitment) algorithms have various security flaws. In this article, we first indicate that the two state-of-art key-based commitment schemes are vulnerable to "Commitment Extract(Decrypt)-then-Reuse Attack" and "Commitment Impersonation Attack" which demolish the unforgeability of the commitment. Then to cover all the existing attacks to commitment algorithms, we redefine a robuster verifiable security model for verifiable OD-ABE. Subsequently, we invent a ciphertext fingerprint (CTfp)-based commitment scheme and give rigorous proof to the proposed commitment scheme, including binding, hiding, unforgeability, and nonrepudiation (traceability) in the random oracle. Next, we apply our CTfp-based commitment to the widely used OD-ABE schemes to provide them robuster verifiability. Finally, the theoretical comparison and simulation experiments are presented to show our new type of commitment algorithm is more secure and practical.
科研通智能强力驱动
Strongly Powered by AbleSci AI