<p>Ciphertext-Policy Attribute-Based Encryption (CP-ABE) provides secure data sharing under fine-grained access control. The encrypted messages can only be decrypted by the users whose attributes match the access criteria. However, traditional CP-ABE has limitation in supporting ciphertext deduplication since the duplicates maybe under the different access structure. In addition, revocation is also important to ensure that an expired user cannot decrypt, even if his attributes satisfy the access policy. In this work, we develop a deduplication-enabled CP-ABE scheme, which allows Cloud Service Provider (CSP) to support deduplication while fine-grained data sharing. Moreover, we design user identity labels and employ proxy re-encryption for efficient revocation in case of user identity change. Furthermore, our security analysis and experiments show that our approach is secure against Ciphertext Only Attacks (COA) and supports efficient deduplication and revocation. In comparison to existing schemes that support deduplication with access control mechanisms, our simulation results demonstrate that we achieve a higher rate of deduplication.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Deduplication-enabled CP-ABE with revocation

  • Tiantian Zhou,
  • Zehui Tang,
  • Shengke Zeng,
  • Minfeng Shao

摘要

Ciphertext-Policy Attribute-Based Encryption (CP-ABE) provides secure data sharing under fine-grained access control. The encrypted messages can only be decrypted by the users whose attributes match the access criteria. However, traditional CP-ABE has limitation in supporting ciphertext deduplication since the duplicates maybe under the different access structure. In addition, revocation is also important to ensure that an expired user cannot decrypt, even if his attributes satisfy the access policy. In this work, we develop a deduplication-enabled CP-ABE scheme, which allows Cloud Service Provider (CSP) to support deduplication while fine-grained data sharing. Moreover, we design user identity labels and employ proxy re-encryption for efficient revocation in case of user identity change. Furthermore, our security analysis and experiments show that our approach is secure against Ciphertext Only Attacks (COA) and supports efficient deduplication and revocation. In comparison to existing schemes that support deduplication with access control mechanisms, our simulation results demonstrate that we achieve a higher rate of deduplication.