为满足云存储密态数据高效灵活的访问需求,提出支持策略更新的外包属性加密方案。以经典的属性加密方案为基础模块,采用类密钥盲化方法和外包解密技术,在确保明文数据和用户私钥不泄露的条件下,实现密文访问策略的代理更新,同时切实有效地降低终端用户的解密计算量。方案支持非单调的访问结构,在标准模型和假设下可证明具有选择IND-CPA安全性和私钥安全性,与文献同类方案相比,实现了安全性和终端访问效率的进一步优化。
In order to achieve the efficient and flexible access control for the encrypted data stored in the cloud, an outsourced attribute-based encryption scheme with policy update was proposed. Based on the standard attribute-based encryption scheme, the functionality of policy update from delegation for a ciphertext without revealing any confidential information of the plaintext and private keys by utilizing the techniques of key blinding and outsourcing decryption was accomplished. Simultaneously, the decryption overhead for a user to recover the plaintext was effectively reduced. The scheme supports non-monotonic access structure and can be proved to have selective IND-CPA security and private key security under standard assumptions, respectively, in the standard model. Compared with similar schemes from literatures, the scheme provides better security and efficiency.