如何有效保护无线体域网(WBAN)中数据共享时的数据安全是一个亟待解决的关键问题。传统的CP-ABE机制具有"一对多"的数据安全通信功能,适用于WBAN中的访问控制,但运算复杂度高且不支持属性撤销。充分考虑WBAN节点资源的有限性和用户属性的动态性,提出一种在标准模型下CPA安全、支持属性撤销、加密和解密安全外包计算的CP-ABE方案。与已有的方案相比,提出的方案在保证安全性的同时,终端的运算负担大为减少,且可以实时、细粒度地撤销用户属性。
How to effectively protect the security of data sharing in WBAN was a key problem to be solved urgently. The traditional CP-ABE mechanism had a "one to many" data security communication function which was suitable for access control in WBAN, but it had high computational complexity and did not support attribute revocation. Fully considering of limitations on computation and storage of sensor nodes and dynamic user attribute in WBAN, a CP-ABE scheme was proposed which was provably secure against CPA under the standard model and supported attributes revocation, outsourced encryption and decryption. Compared with the proposed schemes, the computation burden on senor nodes is greatly reduced and the user's attribution can be revoked immediately and fine grained while meeting the demand of its security in the proposed scheme.