In Controlled Functional Encryption (C-FE), a policy parameter is introduced during encryption to restrict how the decryptor can decrypt and compute the ciphertext, but C-FE shows certain limitations in complex scenarios involving multiple encryptors participating with their data remaining confidential from each other. To overcome these limitations and leverage the advantages of Multi-Client Functional Encryption (MCFE) and Attribute-Based Encryption (ABE), we extend C-FE, introducing a new primitive termed Controlled Multi-Client Functional Encryption for Flexible Access Control (CMCFE-FAC). This primitive introduces several key innovations: firstly, our CMCFE-FAC scheme combines MCFE to support multiple encryptors, enabling independent encryption and ensuring data privacy and security. Secondly, CMCFE-FAC combines attribute-based mechanisms to support dynamic access control, expanding traditional access control policies and enhancing their flexibility. Thirdly, we formalize the definition and security model for CMCFE-FAC, propose a CMCFE-FAC scheme tailored for the inner product function, and demonstrate the scheme’s security based on the DBDH assumption. Finally, theoretical analysis and experimental results are provided to illustrate its effectiveness and security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Controlled Multi-client Functional Encryption for Flexible Access Control

  • Mingwu Zhang,
  • Yulu Zhong,
  • Yifei Wang,
  • Yuntao Wang

摘要

In Controlled Functional Encryption (C-FE), a policy parameter is introduced during encryption to restrict how the decryptor can decrypt and compute the ciphertext, but C-FE shows certain limitations in complex scenarios involving multiple encryptors participating with their data remaining confidential from each other. To overcome these limitations and leverage the advantages of Multi-Client Functional Encryption (MCFE) and Attribute-Based Encryption (ABE), we extend C-FE, introducing a new primitive termed Controlled Multi-Client Functional Encryption for Flexible Access Control (CMCFE-FAC). This primitive introduces several key innovations: firstly, our CMCFE-FAC scheme combines MCFE to support multiple encryptors, enabling independent encryption and ensuring data privacy and security. Secondly, CMCFE-FAC combines attribute-based mechanisms to support dynamic access control, expanding traditional access control policies and enhancing their flexibility. Thirdly, we formalize the definition and security model for CMCFE-FAC, propose a CMCFE-FAC scheme tailored for the inner product function, and demonstrate the scheme’s security based on the DBDH assumption. Finally, theoretical analysis and experimental results are provided to illustrate its effectiveness and security.