已有的策略隐藏属性加密(ABE,attribute-based encryption)方案只支持受限的访问结构,策略表达能力弱,基于此提出一种新的访问树结构,使属性隐藏和秘密共享能够应用到"与"门、"或"门和"门限"门中。并且,利用合数阶双线性群构造了一种基于访问树的策略隐藏方案,并通过双系统加密的概念证明了方案的安全性。分析和实验验证表明,方案在实现复杂访问结构的策略隐藏的同时,并没有过多地增加计算开销,在实际应用过程中更加灵活和有效。
The existing policies-hidden attribute-based encryption(ABE) schemes could only support a limited access structure, which resulted in weak expressiveness. A new structure of access tree was thus proposed to integrate attribute hiding and secret sharing into "and" gate, "or" gate and "threshold" gate. Then, a tree-based policies-hidden scheme was constructed by using composite order bilinear groups. Under dual system encryption, the scheme was proved to be secure. Furthermore, the analysis and experiment demonstrate that the scheme realize policies-hidden in the complex access structure without increasing the overhead of computation. As a result, it is more feasible and flexible for applications.