Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing

Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
复制标题

DOI:
10.1016/j.future.2017.01.026
复制
发表时间:
2018-01-01
影响因子:
7.5
通讯作者:
Guo, Fuchun
Guo, Fuchun
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jiang, Yinhao;Susilo, Willy;Guo, Fuchun

文献摘要

被引文献

相似文献

在雾计算中,雾与云之间脆弱的连接导致了认证和授权问题。最近,斯托伊梅诺维奇、温、黄和栾通过采用独立认证(SAA)的概念并为其在大型动态信息系统中的安全性配备基于属性的加密(ABE),引入了一种潜在的解决方案。在这样的系统中,用户的访问权限可以描述为与其私钥相关联的一组属性。在本文中,我们注意到,如果用户能够为其部分访问权限生成一个新的私钥,这可能会导致一些不良情况,违反访问控制策略。有趣的是,到目前为止,还没有工作详细研究或解决这个问题。我们指出这是ABE系统中存在的一种“特性”,我们称之为“密钥委托滥用”。存在密钥委托滥用问题的ABE系统将阻碍这些系统在实践中的应用。在这项工作中,我们在文献中首次解决了密文策略基于属性加密(CPABE)系统中的“密钥委托滥用”问题。我们引入了一种新机制来增强CP - ABE方案,以防止这种密钥委托滥用问题。我们将这种特性的安全要求形式化,随后构建了一个满足新安全要求的CP - ABE方案。我们还展示了我们的方案在可追踪CP - ABE中的一个应用,在其中“叛徒”,即泄露其密钥的用户,可以被追踪。(C)2017爱思唯尔B.V.保留所有权利。
In Fog Computing, fragile connection between Fog and Cloud causes problems of the authentication and authorization. Recently, Stojmenovic, Wen, Huang and Luan introduced a potential solution by adopting the concept of Stand-Alone Authentication (SAA) and equipped it with Attribute-based encryption (ABE) for its security in a large and dynamic information system. In such a system, a user's access right can be described as a set of attributes linking to his/her private key. In this paper, we note that if a user can generate a new private key for a portion of his/her access right, this could potentially lead to some undesirable situations, which violates the access control policy. Interestingly, to date, there is no work that looks into this matter in detail nor addresses it. We point out that this is a "property" that exists in ABE systems, which we refer to "key-delegation abuse". ABE systems that suffer from key-delegation abuse will hinder the adoption of these systems in practice. In this work, for the first time in the literature, we address the "key-delegation abuse" problem in Ciphertext-policy Attribute-based Encryption(CPABE) systems. We introduce a new mechanism to enhance CP-ABE schemes that provide protections against this key-delegation abuse issue. We formalize the security requirements for such a property, and subsequently construct a CP-ABE scheme that satisfies the new security requirements. We also present an application of our scheme to a traceable CP-ABE, where the "traitors", i.e. the users who have leaked their keys, can be traced. (C) 2017 Elsevier B.V. All rights reserved.