计算机科学
撤销
计算机安全
加密
密文
基于属性的加密
云计算
明文
密码学
认证(法律)
可追溯性
随机预言
保密
密钥托管
方案(数学)
公钥密码术
叛徒追踪
前向保密
信息隐私
密码原语
计算机网络
钥匙(锁)
追踪
通道结构
云存储
吊销列表
报文认证码
语义安全
作者
Jiguo Li,Enfan Zhang,Yichen Zhang,Jianting Ning,Jian Shen
标识
DOI:10.1109/tdsc.2025.3631722
摘要
With the rapid advancement of cloud technology, ciphertext-policy attribute-based encryption (CP-ABE) schemes are highly suited to cloud storage environments. In order to protect sensitive information, policy-hidden CP-ABE has garnered significant attention. However, these schemes are vulnerable to fake policy attacks, where an attacker may introduce false policy and leak system information. To address this issue, we propose a traceable and revocable CP-ABE scheme with policy authentication (TR-PA-ABE). This scheme incorporates a policy checker, which is able to verify whether a ciphertext is encrypted under the correct access policy without revealing any confidential information. Additionally, it features a traceability mechanism that leverages white-box tracing to identify users who leak their keys by embedding user identities within their attribute keys. Our direct revocation method efficiently updates ciphertexts associated with revoked users without impacting the keys of other users, thus minimizing computing overhead. We formally prove that TR-PA-ABE is indistinguishable secure under chosen plaintext attacks (IND-CPA) based on the decision parallel $q$-bilinear Diffie-Hellman exponent assumption. Furthermore, our performance evaluation illustrates the practicality and efficiency of TR-PA-ABE.
科研通智能强力驱动
Strongly Powered by AbleSci AI