| 引用本文: | 王经纬,夏志华,宁建廷,许胜民,李朋林.基于变色龙哈希的可撤销注册属性加密方案.软件学报,,():1-16 |
| |
|
| |
|
|
| 本文已被:浏览 290次 下载 128次 |
 码上扫一扫! |
|
|
| 基于变色龙哈希的可撤销注册属性加密方案 |
|
王经纬1, 夏志华1, 宁建廷2,3,4, 许胜民3,4, 李朋林5
|
|
1.暨南大学 网络空间安全学院, 广东 广州 510632;2.武汉大学 国家网络安全学院, 湖北 武汉 430072;3.福建师范大学 计算机与网络空间安全学院, 福建 福州 350117;4.分析数学及应用教育部重点实验室(福建师范大学), 福建 福州 350117;5.上海同态信息技术有限责任公司, 上海 200030
|
|
| 摘要: |
| 属性加密方案能够实现基于用户属性的细粒度访问控制, 但密钥的生成依赖于一个授权中心来完成, 容易带来密钥泄露的安全隐患. 注册加密方案通过引入用户注册、公钥聚合等机制, 缓解了由授权中心带来的安全风险. 然而, 目前基于多sRABE子方案并行构建的注册属性加密方案在用户动态增减时需要频繁执行公钥重聚合操作, 其计算与存储开销随子方案数量线性增长, 难以适用于用户频繁变化的场景. 针对上述不足, 提出一种基于变色龙哈希的可撤销注册属性加密方案, 在单一sRABE框架下实现了高效的用户注册与撤销. 方案引入陷门可控的变色龙哈希函数, 通过公钥聚合方对公钥一致性的维护, 新用户加入时无需执行系统级主公钥聚合, 用户撤销仅需对注册槽状态进行标记, 从而避免了多子方案结构带来的计算开销. 在效率方面, 方案对新用户加入阶段的计算开销进行了分析, 结果表明该过程的计算复杂度仅与用户属性数量相关, 与系统用户规模无关. 安全性分析表明, 方案在不可区分模型下可以抵抗选择明文攻击. |
| 关键词: 注册加密 属性加密 用户撤销 变色龙哈希 数据共享 |
| DOI:10.13328/j.cnki.jos.007647 |
| 分类号:TP309 |
| 基金项目:国家自然科学基金(12441101, 62372108, 62402109, 62425205, 62572123) |
|
| Revocable Registered Attribute-based Encryption Scheme Using Chameleon Hash |
|
WANG Jing-Wei1, XIA Zhi-Hua1, NING Jian-Ting2,3,4, XU Sheng-Min3,4, LI Peng-Lin5
|
|
1.College of Cyber Security, Jinan University, Guangzhou 510632, China;2.School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China;3.College of Computer and Cyber Security, Fujian Normal University, Fuzhou 350117, China;4.Key Laboratory of Analytical Mathematics and Applications (Fujian Normal University), Fuzhou 350117, China;5.Shanghai Tongtai Information Technology Co. Ltd., Shanghai 200030, China
|
| Abstract: |
| Attribute-based encryption (ABE) enables fine-grained access control based on user attributes, but it relies on a centralized authority for key generation, which may cause security risks such as key leakage. Registered-based encryption schemes mitigate this issue using mechanisms such as user registration and public key aggregation. However, existing constructions based on multiple parallel sRABE sub-schemes require frequent public key re-aggregation when users dynamically join or leave, leading to computational and storage overhead that grows linearly with the number of sub-schemes. Therefore, these constructions are difficult to apply in scenarios with frequent user changes. To overcome this limitation, this study proposes a chameleon-hash-based revocable registered attribute-based encryption scheme that achieves efficient user registration and revocation within a single sRABE framework. By introducing a trapdoor-controllable chameleon hash function and allowing the public key aggregator to maintain public key consistency, new users can be registered without system-level public key re-aggregation. Meanwhile, user revocation only requires marking the status of registration slots, thus avoiding the computational overhead caused by the multi-sub-scheme structure. In terms of efficiency, the computational overhead of the new-user registration phase is analyzed, and the results show that the computational complexity of this process depends only on the number of user attributes and is independent of the number of users in the system. Security analysis shows that the proposed scheme is secure against chosen-plaintext attacks under the indistinguishability model. |
| Key words: registered-based encryption attribute-based encryption (ABE) user revocation chameleon hash data sharing |
|
|
|
|