Attribute-Based Encryption with Fast Decryption

Attribute-Based Encryption with Fast Decryption
复制标题

DOI:
10.1007/978-3-642-36362-7_11
复制
发表时间:
2013-02
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
S. Hohenberger;Brent Waters
S. Hohenberger;Brent Waters
中科院分区:
其他
文献类型:
--
作者:
S. Hohenberger;Brent Waters

文献摘要

被引文献

相似文献

基于属性的加密(ABE)是公钥加密的一种设想,它允许用户根据用户属性对消息进行加密和解密。这种功能是有代价的。在一个典型的实现中,密文的大小与关联的属性数成正比,解密时间与解密过程中使用的属性数成正比。具体来说,许多实际的ABE实现需要在解密过程中使用每个属性一个配对操作。我们将注意力限制在没有系统范围的界限或限制的表达系统上,例如对密文或私钥中使用的属性的数量进行限制。在这种情况下,我们提出了第一个密钥策略ABE系统,其中密文可以解密一个常数的配对。我们表明,GPSW密文可以解密只有2对增加的私钥大小的一个因素,|Γ|其中,r是出现在私钥中的不同属性的集合。然后,我们提出了一个广义的建设,允许每个系统用户独立地调整各种效率的权衡,他们喜欢的频谱上的极端是GPSW的一端和我们的非常快的计划。此调优不需要更改公共参数或加密算法。讨论了选择个性化用户优化方案的策略。最后,我们讨论了如何将这些想法可以转化为密文策略ABE设置在一个更高的成本。
Attribute-based encryption (ABE) is a vision of public key encryption that allows users to encrypt and decrypt messages based on user attributes. This functionality comes at a cost. In a typical implementation, the size of the ciphertext is proportional to the number of attributes associated with it and the decryption time is proportional to the number of attributes used during decryption. Specifically, many practical ABE implementations require one pairing operation per attribute used during decryption.This work focuses on designing ABE schemes with fast decryption algorithms. We restrict our attention to expressive systemswithoutsystem-wide bounds or limitations, such as placing a limit on the number of attributes used in a ciphertext or a private key. In this setting, we present the first key-policy ABE system where ciphertexts can be decrypted with a constant number of pairings. We show that GPSW ciphertexts can be decrypted with only 2 pairings by increasing the private key size by a factor of |Γ|, where Γ is the set of distinct attributes that appear in the private key. We then present a generalized construction that allows each system user to independently tune various efficiency tradeoffs to their liking on a spectrum where the extremes are GPSW on one end and our very fast scheme on the other. This tuning requires no changes to the public parameters or the encryption algorithm. Strategies for choosing an individualized user optimization plan are discussed. Finally, we discuss how these ideas can be translated into the ciphertext-policy ABE setting at a higher cost.