属性分级并部分盲化的多机构CP-ABE

MULTI-AUTHORITY CP-ABE SCHEME WITH ATTRIBUTE CLASSIFICATION AND PARTIAL BLINDING

  • 摘要: 针对CP-ABE的访问策略中有些属性可能会泄露一些隐私或敏感信息,提出盲化敏感属性的多属性监管机构CP-ABE方案。该方案根据属性和敏感信息之间的相关程度将属性分成三类:全局敏感、局部敏感和一般。加密时盲化访问策略中出现敏感属性,而一般属性以明文形式出现。两个属性监管机构协调预判用户的解密能力,进而避免徒劳的解密运算。这样不仅能针对性地防止访问策略泄露敏感信息,而且通过保留一般属性的明文出现,能降低加解密的计算代价,从而得到策略机密性和密码系统的效率之间的更好折中。

     

    Abstract: In Ciphertext-Policy Attribute-Based Encryption (CP-ABE), some attributes in the access policy may disclose privacy or sensitive information. Therefore, a multi-authority CP-ABE scheme with obfuscated sensitive attributes is proposed. According to the correlation between attributes and sensitive information, the scheme divides attributed into three categories: global sensitive, local sensitive and general. Sensitive attributes in access policies during encryption were obfuscate, and the non-sensitive attributes remained in a plain-text format. Two attribute authorities cooperated to predict the user's decryption ability to avoid useless decryption attempts. Thus, we could not only prevent revealing sensitive information but also reduce the time and space cost of encryption and decryption by keeping the non-sensitive attributes public, consequently achieving a better tradeoff between policy confidentiality and the efficiency of the cryptosystem.

     

/

返回文章
返回