摘要
为了减少基于密文策略的属性加密(ciphertext-policy attribute-based encryption,CP-ABE)方案中用户和数据拥有者(data owner,DO)的计算量,该文提出一种方法,将解密密钥分为2部分,其中一部分存放在用户端,另一部分存储于代理者(例如云服务提供商CSP),使得属性撤销操作不会对用户产生影响,并且由于CSP进行了部分解密工作,使得用户的解密计算量降低。分析证明该方案可以减小用户和DO的计算量和通信量,并且可抵抗选择明文攻击。
The computational overhead for both the users and the data owners (DO) in ciphertext policy attribute-based encryption (CP ABE) schemes is reduced by dividing the deeryption key into two parts. One part is stored with the user while the other part is stores in the proxy (such as the cloud service provider, CSP) side. Users are not affected by attribute revocation and the computational overhead of the users is reduced because CSP does part of the decryption. The scheme reduces the computation and communication overhead for users and DO and is secure against chosen plaintext attacks.
出处
《清华大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2013年第12期1664-1669,共6页
Journal of Tsinghua University(Science and Technology)
基金
中央高校基本科研业务费专项资金资助项目(2012JBM004)
关键词
云存储
访问控制
外包解密
属性加密
cloud storage
access control
outsourced deeryption
attribute-based encryption