| 本文已被:浏览 4912次 下载 8760次 |
 码上扫一扫! |
|
|
| 密文策略的属性基并行密钥隔离加密 |
|
陈剑洪1,2,3, 陈克非1,3, 龙宇1, 万中美4, 于坤2, 孙成富2, 陈礼青2
|
|
1.上海交通大学计算机科学与工程系, 上海 200240;2.淮阴工学院计算机工程学院, 江苏淮安 223003;3.上海市可扩展计算与系统重点实验室(上海交通大学), 上海 200240;4.河海大学理学院, 江苏南京 210098
|
|
| 摘要: |
| 对于公钥密码体制来说,私钥泄漏是一种十分严重的威胁.传统密码系统可以通过撤销公钥来应对私钥泄漏,但在属性基密码系统里,公钥由属性集合表示,对这些属性集合的撤销不太可行.目前,密钥隔离机制是减轻密钥泄漏所带来危害的一种有效方法.为了处理属性基密码系统中的密钥泄露问题,将并行密钥隔离机制引入到密文策略的属性基加密中,提出了密文策略的属性基并行密钥隔离加密(ciphertext policy attribute-based parallel key-insulated encryption,简称 CPABPKIE)的概念.在给出 CPABPKIE 的形式化定义和安全模型的基础上,构建了一个不需要随机预言机模型的选择ID安全的CPABPKIE方案.所提方案允许较频繁的临时私钥更新,同时可以使协助器密钥泄漏的几率保持较低,因此增强了系统防御密钥泄漏的能力. |
| 关键词: 密文策略 属性基 加密 并行密钥隔离 |
| DOI:10.3724/SP.J.1001.2012.04183 |
| 分类号: |
| 基金项目:国家自然科学基金(60970111, 61133014, 60903189, 60903020, 61103183); 淮安市科技支撑计划(工业)(HAG2011044, HAG2011045) |
|
| Ciphertext Policy Attribute-Based Parallel Key-Insulated Encryption |
|
CHEN Jian-Hong1,2,3, CHEN Ke-Fei1,3, LONG Yu1, WAN Zhong-Mei4, Yu Kun2, SUN Cheng-Fu2, CHEN Li-Qing2
|
|
1.Department of Computer Science and Engineering, Shanghai Jiaotong University, Shanghai 200240, China;2.School of Computer Engineering, Huaiyin Institute of Technology, Huaian 223003, China;3.Shanghai Key Laboratory of Scalable Computing and Systems (Shanghai Jiaotong University), Shanghai 200240, China;4.College of Science, Hohai University, Nanjing 210098, China
|
| Abstract: |
| The key-exposure problem has perhaps been the most devastating attack on a cryptosystem.Conventional public key cryptosystems can revoke public keys in the case of key-exposure. However, the publickey for an attribute-based scheme represents an attribute set should not be changed. Key-Insulation is a crucialtechnique for protecting private keys. To deal with the key-exposure problems in an attribute-based cryptosystem,this paper extends the parallel key-insulated mechanism to ciphertext policy attribute-based encryption scenariosand introduces the primitive of ciphertext policy attribute-based parallel key-insulated encryption (CPABPKIE).After formalizing the definition and security notions for CPABPKIE, a concrete CPABPKIE scheme is presented.The security the proposed CPABPKIE scheme can be proved in the selective-ID model. The new primitive does notincrease the risk of helper key-exposure, and allows frequent key updating. |
| Key words: ciphertext policy attribute-based encryption parallel key-insulated |