首页> 外文会议>European symposium on research in computer security >Concessive Online/Offline Attribute Based Encryption with Cryptographic Reverse Firewalls-Secure and Efficient Fine-Grained Access Control on Corrupted Machines
【24h】

Concessive Online/Offline Attribute Based Encryption with Cryptographic Reverse Firewalls-Secure and Efficient Fine-Grained Access Control on Corrupted Machines

机译:使用加密反向防火墙的基于在线/离线属性的加密技术,可在损坏的计算机上实现安全有效的细粒度访问控制

获取原文

摘要

Attribute based encryption (ABE) has potential to be applied in various cloud computing applications. However, the Snowden revelations show that powerful adversaries can corrupt users' machines to compromise the security, and many implementations of provably secure encryption schemes may present undetectable vulnerabilities that can expose secret, e.g., the scheme still works properly even some backdoors have been stealthily engineered on users' machines. Undoubtedly, ABE is also facing the above security threats. Recently, Mironov and Stephens-Davidowitz proposed cryptographic reverse firewall (CRF) to solve the problem. Unfortunately, no CRF-based protection for ABE has been proposed so far due to the complex system model and the extra access structure component. Besides, the encryption scheme in the CRF framework will suffer double computation latency, which is worse for ABE that has already yielded expensive operations. In this paper, we propose a concessive online/offline ciphertext-policy attribute based encryption with cryptographic reverse firewalls (COO-CP-ABE-CRF), which can resist the exfiltration of secret information and achieve selective CPA security. Furthermore, compared with the original scheme without CRF, our scheme reduces the total computation cost by half. Moreover, we develop an extensible library called libabe that is compatible with Android devices, and we implement the prototype on a laptop and a mobile phone. The experimental results indicate that the scheme is efficient and practical.
机译:基于属性的加密(ABE)有潜力应用于各种云计算应用程序中。但是,斯诺登(Snowden)的启示表明,强大的对手可能会破坏用户的计算机,从而破坏安全性,并且许多可证明安全的加密方案的实现可能会呈现出无法检测到的漏洞,这些漏洞可能会泄露机密信息,例如,即使某些后门经过了秘密设计,该方案仍然可以正常工作。在用户的计算机上。无疑,ABE也面临着上述安全威胁。最近,Mironov和Stephens-Davidowitz提出了密码反向防火墙(CRF)来解决该问题。不幸的是,由于复杂的系统模型和额外的访问结构组件,到目前为止,尚未提出基于CRF的ABE保护。此外,CRF框架中的加密方案将遭受两倍的计算延迟,这对于已经产生了昂贵操作的ABE来说更糟。在本文中,我们提出了一种使用加密反向防火墙(COO-CP-ABE-CRF)的基于特许/在线/离线密文策略策略属性的加密方法,该方法可以抵抗秘密信息的泄露并实现选择性的CPA安全性。此外,与没有CRF的原始方案相比,我们的方案将总计算成本降低了一半。此外,我们开发了一个名为libabe的可扩展库,该库与Android设备兼容,并且在便携式计算机和移动电话上实现了原型。实验结果表明该方案是有效和实用的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号