Time-Based Direct Revocable Ciphertext-Policy Attribute-Based Encryption with Short Revocation List

Time-Based Direct Revocable Ciphertext-Policy Attribute-Based Encryption with Short Revocation List
复制标题

DOI:
10.1007/978-3-319-93387-0_27
复制
发表时间:
2018-07
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Joseph K. Liu;Tsz Hon Yuen;Peng Zhang;K. Liang
Joseph K. Liu;Tsz Hon Yuen;Peng Zhang;K. Liang
中科院分区:
其他
文献类型:
--
作者:
Joseph K. Liu;Tsz Hon Yuen;Peng Zhang;K. Liang

文献摘要

被引文献

相似文献

本文提出了一种有效的可验证的基于属性的密文策略加密方案(CP-ABE)。我们基于直接撤销方法,通过将撤销列表嵌入到密文中。然而,由于撤销列表会随着时间的推移而变长,我们进一步利用这一点,提出了一个秘密密钥时间验证技术,使用户将有他们的密钥到期的日期和撤销列表只需要包括那些用户密钥撤销之前,他们的预期到期日期(例如,那些用户密钥已被盗到期前)。这些密钥可以在其到期日期之后从撤销列表中移除,以便保持撤销列表较短,因为这些密钥不能再用于解密在其到期时间之后生成的密文。该技术源自分层基于身份的加密(HIBE)机制,因此时间段具有分层结构:年,月,日。全年有效的用户可以解密与一年中任何一个月或任何一天的时间段相关联的任何密文。通过使用该技术,可以大大减少公开参数和用户密钥的大小。这种技术的一个额外优势是支持用户有效性的不连续性(例如,无薪休假)。
In this paper, we propose an efficient revocable Ciphertext-Policy Attribute-Based Encryption (CP-ABE) scheme. We base on the direct revocation approach, by embedding the revocation list into ciphertext. However, since the revocation list will grow longer as time goes by, we further leverage this by proposing a secret key time validation technique so that users will have their keys expired on a date and the revocation list only needs to include those user keys revoked before their intended expired date (e.g. those user keys which have been stolen before expiry). These keys can be removed from the revocation list after their expiry date in order to keep the revocation list short, as these keys can no longer be used to decrypt ciphertext generated after their expiry time. This technique is derived from Hierarchical Identity-based Encryption (HIBE) mechanism and thus time periods are in hierarchical structure: year, month, day. Users with validity of the whole year can decrypt any ciphertext associated with time period of any month or any day within the year. By using this technique, the size of public parameters and user secret key can be greatly reduced. A bonus advantage of this technique is the support of discontinuity of user validity (e.g. taking no-paid leave).