On Anonymous Attribute Based Encryption

On Anonymous Attribute Based Encryption
复制标题

DOI:
10.1007/978-3-319-26961-0_23
复制
发表时间:
2015-12
期刊:
--
影响因子:
--
通讯作者:
Payal Chaudhari;M. Das;A. Mathuria
Payal Chaudhari;M. Das;A. Mathuria
中科院分区:
其他
文献类型:
--
作者:
Payal Chaudhari;M. Das;A. Mathuria

文献摘要

被引文献

相似文献

基于属性的加密(ABE)在数据机密性和存储在公共云中的共享数据的细粒度访问控制方面具有巨大的应用范围。经典的ABE方案需要将访问策略沿着在密文中,其中访问策略描述接收方所需的属性值。作为接收机的属性(即,用户)的身份,可能会导致密文中某些敏感信息的泄露(例如,明文的性质、从接收者寻求的动作)。因此,在使用被称为匿名ABE(AABE)的ABE方案发送密文的同时匿名化属性,是一个有前途的原语,用于执行细粒度的访问控制,以及保护隐私的接收器。在ASIACCS 2013中,Zhang等人提出了一种使用匹配然后解密技术的AABE方案[1],其中在执行解密之前,用户执行匹配操作,以确保用户是否是密文的预期接收者。我们发现Zhanget al.的方案[1]是不安全的,特别是它不能实现接收者的匿名性。在本文中,我们讨论了安全弱点Zhang等人。的方案。我们表明,对手可以成功地检查是否需要一个属性来解密密文,反过来,揭示接收者的身份。我们还提出了一个改进的方案,以克服Zhang等人的安全弱点。的方案。
Attribute Based Encryption (ABE) has found enormous scope in data confidentiality and fine-grained access control of shared data stored in public cloud. Classical ABE schemes require attaching the access policy along with the ciphertext, where the access policy describes required attribute values of a receiver. As attributes of a receiver (i.e., user) could relate to the identity of users, it could lead to reveal some sensitive information of the ciphertext (e.g. nature of plaintext, action sought from of receiver) for applications like healthcare, financial contract, bureaucracy, etc. Therefore, anonymizing attributes while sending ciphertext in use of ABE schemes, known as Anonymous ABE (AABE), is a promising primitive for enforcing fine-grained access control as well as preserving privacy of the receiver. In ASIACCS 2013, Zhanget al.proposed an AABE scheme using thematch-then-decrypt[1] technique, where before performing decryption, the user performs a match operation that ensures a user whether he is the intended recipient for the ciphertext or not. We found that Zhanget al.’s scheme [1] is not secure, in particular, it fails to achieve receiver’s anonymity. In this paper, we discuss the security weaknesses of Zhanget al.’s scheme. We show that an adversary can successfully check whether an attribute is required to decrypt a ciphertext, in turn, reveal the receiver’s identity. We also suggest an improved scheme to overcome the security weakness of Zhanget al.’s scheme.