Revisiting Attribute-Based Encryption With Verifiable Outsourced Decryption

Revisiting Attribute-Based Encryption With Verifiable Outsourced Decryption
复制标题

通过可验证的外包解密重新审视基于属性的加密

DOI:
10.1109/tifs.2015.2449264
复制
发表时间:
2015-10-01
影响因子:
6.8
通讯作者:
Wang, Mingsheng
Wang, Mingsheng
中科院分区:
计算机科学1区
文献类型:
--
作者:
Lin, Suqing;Zhang, Rui;Wang, Mingsheng

文献摘要

被引文献

相似文献

基于属性的加密(ABE)是一种很有前途的云存储加密数据细粒度访问控制技术,但ABE中涉及的解密对于资源受限的前端用户来说通常过于昂贵,这极大地阻碍了其实际普及。为了减少用户恢复明文的解密开销,绿色等人建议将大部分解密工作外包,而不泄露实际数据或私钥。为了确保第三方服务诚实地计算外包工作,Lai等人对ABE的解密提供了可验证性要求,但他们的方案使底层ABE密文的大小和计算成本增加了一倍。粗略地说,他们的主要思想是使用并行加密技术,而其中一个加密组件用于验证目的。因此,带宽和计算成本加倍。在本文中,我们研究同样的问题。特别是,我们提出了一个更有效的和通用的ABE与可验证的外包解密的基础上基于属性的密钥封装机制,密钥加密方案和承诺计划的建设。在标准模型下,证明了所构造的ABE方案的安全性和验证可靠性。最后,我们实例化我们的计划与具体的积木。与Lai et al.的方案,我们的方案减少了带宽和计算成本几乎一半。
Attribute-based encryption (ABE) is a promising technique for fine-grained access control of encrypted data in a cloud storage, however, decryption involved in the ABEs is usually too expensive for resource-constrained front-end users, which greatly hinders its practical popularity. In order to reduce the decryption overhead for a user to recover the plaintext, Green et al. suggested to outsource the majority of the decryption work without revealing actually data or private keys. To ensure the third-party service honestly computes the outsourced work, Lai et al. provided a requirement of verifiability to the decryption of ABE, but their scheme doubled the size of the underlying ABE ciphertext and the computation costs. Roughly speaking, their main idea is to use a parallel encryption technique, while one of the encryption components is used for the verification purpose. Hence, the bandwidth and the computation cost are doubled. In this paper, we investigate the same problem. In particular, we propose a more efficient and generic construction of ABE with verifiable outsourced decryption based on an attribute-based key encapsulation mechanism, a symmetric-key encryption scheme and a commitment scheme. Then, we prove the security and the verification soundness of our constructed ABE scheme in the standard model. Finally, we instantiate our scheme with concrete building blocks. Compared with Lai et al.'s scheme, our scheme reduces the bandwidth and the computation costs almost by half.