Fine-grained access control schemes with fully hidden attributes for cloud systems
摘要
Providing fine-grained access control for cloud data is an essential foundation for cloud system applications. Attribute-based encryption is a standard method for fine-grained access control, but its access policy may leak users’ privacy. Although several fully hidden attribute schemes have been proposed, none can resist the guessing attack. In this article, we analyze Hao et al.’s scheme and show their scheme cannot hide attributes. We propose an improved scheme based on the keyed attribute Bloom filter and an efficient and expressive fully hidden scheme based on the keyed HASH function. Both of these schemes can resist the dictionary attack and the guessing attack. We improve Waters’s schemes to resist the guessing attack, present a new attribute hiding method to resist the dictionary attack and support the linear secret sharing scheme policies with non-injective functions, and design a new attribute Bloom filter to resist the dictionary attack. We present formal definitions for attribute privacy and verifiability and prove that the proposed schemes are secure and achieve attribute privacy and verifiability. The analysis and simulation show that the proposed schemes are practical and offer significant advantages in security, performance, and expressiveness.