摘要
密文策略的属性基加密(CP-ABE)可以实现数据拥有者定义的基于外挂加密数据的访问控制,使它在数据分享细粒度访问控制中有着良好的应用前景,然而在实际应用系统中仍然存在属性撤销方面急需解决的问题。在代理重加密技术和CP-ABE技术相结合的方案基础上,引入Shamir的秘密分享技术和树访问结构,实现了门限运算和布尔运算的结合,并且缩短了密钥和密文长度。与之前方案相比,在效率和表达能力方面有了明显的提高,此外该方案在判定双线性假设下是安全的。
Ciphertext-Policy Attribute Based Encryptlon (CP-ABE) can reahze access control ot encrypted aata detmecl by the data owner in the outsourcing system, making it promising on fine-grained access control of shared data. However, there are some problems of attribute revocation in the application system that urgently need to be solved. Based on the scheme of integrating the technique of proxy re-encryption into CP-ABE, this paper achieved the combination of threshold operator with Boolean operators and the shortened length of secret key and ciphertext by adopting the technology of Sharnir secret sharing and the tree access structure. Compared with some other schemes proposed before, some obvious improvements in expression and efficiency in this paper can be found. Besides, this scheme is proved safe on decisional bilinear Diffie-Hellman assumption.
出处
《计算机应用》
CSCD
北大核心
2012年第A01期39-43,共5页
journal of Computer Applications
基金
浙江省教育基金资助项目(Y200805048)