引用本文:赖建昌,黄欣沂,何德彪,陈立全,杨少军.基于SM9的撤销加密方案.软件学报,2024,35(12):5609-5620
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1255次   下载 2289 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于SM9的撤销加密方案
赖建昌1, 黄欣沂2, 何德彪3, 陈立全1, 杨少军4,5
1.东南大学 网络空间安全学院, 江苏 南京 211189;2.香港科技大学 (广州), 广东 广州 511455;3.武汉大学 国家网络安全学院, 湖北 武汉 430073;4.福建师范大学 数学与统计学院, 福建 福州 350117;5.分析数学及应用教育部重点实验室 (福建师范大学), 福建 福州 350117
摘要:
撤销加密是一种反向的广播加密技术, 加密算法的输入不是接收者集合而是撤销用户的集合, 系统中所有不在撤销集合中的用户都可以正确解密密文, 撤销集合中的所有用户合谋也无法获取加密数据的内容. 与广播加密相比, 撤销加密更适用于接收者为系统中大多数用户或需要撤销部分用户未来解密权限的场景. 基于我国商用标识密码提出一个基于SM9的撤销加密方案, 密文的长度是固定的, 与撤销用户集合的大小无关. 基于广义群模型中的困难假设, 证明方案在随机谕言机模型下具有选择明文的安全性. 最后, 分析方案的性能对比结果可知, 所提方案与目前基于身份的撤销加密方案在计算复杂度和存储复杂度方面相比性能相当.
关键词:  撤销加密  SM9  广播加密  可证明安全  定长密文
DOI:10.13328/j.cnki.jos.007041
分类号:TP309
基金项目:国家自然科学基金(62032005, U21A20466, U22B2026, 62272104); 东南大学新进教师科研启动项目(RF1028623200)
Revocation Encryption Scheme Based on SM9
LAI Jian-Chang1, HUANG Xin-Yi2, HE De-Biao3, CHEN Li-Quan1, YANG Shao-Jun4,5
1.School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China;2.The Hong Kong University of Science and Technology (Guangzhou), Guangzhou 511455, China;3.School of Cyber Science and Engineering, Wuhan University, Wuhan 430073, China;4.School of Mathematics and Statistics, Fujian Normal University, Fuzhou 350117, China;5.Key Laboratory of Analytical Mathematics and Applications (Ministry of Education)(Fujian Normal University), Fuzhou 350117, China
Abstract:
Revocation encryption is a negative analogue of broadcast encryption. Unlike broadcast encryption, the input to the encryption algorithm is not a receiver set, but a set of revoked users. All users who are not in the revocation set within the system can decrypt the ciphertext successfully. Users in the revocation set learn nothing about the encrypted data, even in collusion. Compared to broadcast encryption, revocation encryption is more suitable for scenarios where most of the users in the system are the intended recipients and when revoking decryption rights for certain users is required. This study proposes a revocation encryption scheme based on the Chinese identity-based encryption standard SM9. The ciphertext size in the proposed scheme remains constant, and it is independent of the size of the revocation set. Based on a complex assumption in the generic group model, the scheme is proven secure against CPA under the random oracle model. Finally, the performance of the scheme is analyzed, and the results indicate that its computational costs and storage overheads are comparable to the existing revocation encryption schemes.
Key words:  revocation encryption  SM9  broadcast encryption  provable security  constant size ciphertext

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: