• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2022, Vol. 44 ›› Issue (05): 800-809.

• 计算机网络与信息安全 • 上一篇    下一篇

可防止无关属性干扰的属性基加密方案

许城洲1,张文涛1,郎静宏2   

  1. (1.中国航天系统科学与工程研究院,北京 100037;2.中国空间技术研究院,北京 100081)

  • 收稿日期:2021-01-13 修回日期:2021-06-08 接受日期:2022-05-25 出版日期:2022-05-25 发布日期:2022-05-24

An attribute-based encryption scheme preventing irrelevant attributes interference

XU Cheng-zhou1,ZHANG Wen-tao1,LANG Jing-hong2   

  1. (1.China Aerospace Academy of Systems Science and Engineering,Beijing 100037;
    2.China Academy of Space Technology,Beijing 100081,China)
  • Received:2021-01-13 Revised:2021-06-08 Accepted:2022-05-25 Online:2022-05-25 Published:2022-05-24

摘要: 为了提高属性基加密中访问结构的表达能力,同时避免访问结构中无关属性干扰,提出了一种基于简化有序二元决策图(ROBDD)访问结构的CP-ABE方案。该方案中ROBDD访问结构可有效表达具有复杂访问逻辑的访问策略,并可防止无关属性干扰,提高了加密速度。通过RSA属性认证机制进行ROBDD非叶子节点中属性认证,实现了抗串谋攻击和对用户属性集的保护。使用ROBDD中有效路径特征值和加密参数创建多项式,任何有效路径特征值经过多项式计算均可得到加密参数,降低了密文存储开销。该方案实现了用户撤销、用户属性撤销和系统属性撤销。性能分析和实验仿真表明,所提方案有更高的加解密效率,更低的密文存储开销。

关键词: 密文策略属性基加密, 简化有序二元决策图, 多项式, RSA属性认证

Abstract: In order to improve the expressivity of the access structure in attribute-based encryption, and avoid the interference of irrelevant attributes in the access structure,  a ciphertext-policy attribute-based encryption (CP-ABE) scheme based on reduced ordered binary decision diagram (ROBDD) access structure is proposed. The ROBDD access structure in this scheme can effectively express the access policy with complex access logic and prevent the interference of irrelevant attributes, which improves the encryption speed. RSA attribute authentication mechanism is introduced to achieve attribute authentication in non-leaf nodes of ROBDD, which realizes anti-collusion attack and protection of user attribute set. The effective path eigenvalues and encryption parameters in ROBDD are used to create polynomials, and any effective path eigenvalue can get encryption parameters through polynomial calculation, which reduces the cost of ciphertext storage overhead. The scheme implements user revocation, user attribute revocation, and system attribute revocation. Performance analysis and experimental simulation show that the proposed scheme has higher encryption and decryption efficiency, and lower ciphertext storage overhead.


Key words: ciphertext-policy attribute-based encryption, reduced ordered binary decision diagram, polynomial, RSA attribute authentication