采用一种简洁高效的转化方法将Waters的只能抵抗选择明文攻击(Chosen-Plaintext Attack,CPA)的基于属性的加密方案转化为能够抵抗选择密文攻击(Chosen-Ciphertext Attack,CCA)的密钥封装方案,并在此基础上提出了一个标准模型下增强的基于属性的认证密钥协商协议.该协议能够在CK+模型下可证安全.CK+模型是目前关于认证密钥协商协议的最强的安全性定义.本文协议满足弱的完美前向安全性,并能抵抗密钥泄露伪装攻击和临时密钥泄露攻击.相比于现有的基于属性的认证密钥协商协议,本文协议具有更高的通信效率和更强的安全性.
In this paper, we propose an enhanced attribute-based authenticated key agreement (ABAKA) protocol in the standard model. We construct our protocol based on Waters' ciphertext- policy attribute-based encryption with a simple and compact conversion technique to the chosenplaintext attack (CPA) security from the chosen-ciphertext attack (CCA) security. The protocol is provably secure in the CK+ model which provides the strongest definition of security for authenticated key agreement protocol at present. The protocol can provide weak perfect forward secrecy and resist key compromise impersonation and leakage of ephemeral key attacks. Compared with the existing ABAKA protocols, our protocol is more efficient in communication cost and obtains stronger security.