首页 | 官方网站   微博 | 高级检索  
     

支持撤销的多授权中心访问控制方案
引用本文:李勇,雷丽楠.支持撤销的多授权中心访问控制方案[J].北京理工大学学报,2017,37(10):1014-1018.
作者姓名:李勇  雷丽楠
作者单位:北京交通大学电子信息工程学院,北京100044;福建师范大学福建省网络安全与密码技术重点实验室,福建,福州350007;北京交通大学电子信息工程学院,北京,100044
基金项目:中央高校基本科研业务费专项资金资助项目(2016YJS003);国家自然科学基金资助项目(61472032);福建省网络安全与密码技术重点实验室(福建师范大学)开放课题资助项目(15007)
摘    要:为了缓解单授权中心的计算压力,近些年提出了多授权中心的访问控制方案.这些方案对于用户及属性的撤销问题并没有有效地解决.本文提出了一种基于CP-ABE的支持用户和属性撤销的多授权中心访问控制方案.通过引入密钥加密密钥(key encryption key,KEK)树实现用户和属性层级的撤销,同时将计算压力分散给多个授权中心,并将部分解密交给云服务器,减少了用户的计算消耗.通过安全性证明和实验结果表明,方案可以抵御合谋攻击,同时有效地降低撤销过程中密文和密钥更新的消耗时间. ̄ 

关 键 词:访问控制  属性撤销  基于密文策略属性加密  多授权中心  密钥加密密钥
收稿时间:2016/9/28 0:00:00

A Multi-Authorities Access Control Scheme Supporting Revocation
LI Yong and LEI Li-nan.A Multi-Authorities Access Control Scheme Supporting Revocation[J].Journal of Beijing Institute of Technology(Natural Science Edition),2017,37(10):1014-1018.
Authors:LI Yong and LEI Li-nan
Affiliation:1. School of Electronic and Information Engineering, Beijing Jiaotong University, Beijing 100044, China;2. Fujian Provincial Key Laboratory of Network Security and Cryptology, Fujian Normal University, Fuzhou, Fujian 350007, China
Abstract:In recent years, in order to alleviate the pressure on the calculation of a single authorization center, multi-authorities access control schemes were proposed. But these schemes are inefficient in the revocation of user and attribute level. In this paper, a scheme was proposed based on multi-authorities and the key encryption key (KEK) tree was used to achieve revocation. In the scheme, the computation load was distributed to multi-authorities center and partial decryption was transferred to the cloud server. The security proof result shows that the scheme can resist collusion attack, and experiment results show that the scheme can effectively reduce the time consumption of ciphertext and key update in revocation process.
Keywords:access control  attribute revocation  ciphertext-policy attribute-based encryption  multi-authorities  key encryption key
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号