Huang Boxue, Gao Juntao, Li Xuelian
School of Telecommunications Engineering, Xidian University, Xi'an, China.
School of Mathematics and Statistics, Xidian University, Xi'an, China.
J Cloud Comput (Heidelb). 2023;12(1):37. doi: 10.1186/s13677-023-00414-w. Epub 2023 Mar 11.
Cloud file sharing (CFS) has become one of the important tools for enterprises to reduce technology operating costs and improve their competitiveness. Due to the untrustworthy cloud service provider, access control and security issues for sensitive data have been key problems to be addressed. Current solutions to these issues are largely related to the traditional public key cryptography, access control encryption or attribute-based encryption based on the bilinear mapping. The rapid technological advances in quantum algorithms and quantum computers make us consider the transition from the tradtional cryptographic primitives to the post-quantum counterparts. In response to these problems, we propose a lattice-based Ciphertext-Policy Attribute-Based Encryption(CP-ABE) scheme, which is designed based on the ring learing with error problem, so it is more efficient than that designed based on the learing with error problem. In our scheme, the indirect revocation and binary tree-based data structure are introduced to achieve efficient user revocation and dynamic management of user groups. At the same time, in order to further improve the efficiency of the scheme and realize file sharing across enterprises, the scheme also allows multiple authorities to jointly set up system parameters and manage distribute keys. Furthermore, by re-randomizing the user's private key and update key, we achieve decryption key exposure resistance(DKER) in the scheme. We provide a formal security model and a series of security experiments, which show that our scheme is secure under chosen-plaintext attacks. Experimental simulations and evaluation analyses demonstrate the high efficiency and practicality of our scheme.
云文件共享(CFS)已成为企业降低技术运营成本和提高竞争力的重要工具之一。由于云服务提供商不可信,敏感数据的访问控制和安全问题一直是亟待解决的关键问题。当前针对这些问题的解决方案很大程度上与传统公钥密码学、访问控制加密或基于双线性映射的基于属性的加密有关。量子算法和量子计算机的快速技术进步促使我们考虑从传统密码原语向抗量子密码原语的转变。针对这些问题,我们提出了一种基于格的密文策略属性基加密(CP-ABE)方案,该方案基于带误差的环学习问题设计,因此比基于带误差学习问题设计的方案更高效。在我们的方案中,引入了间接撤销和基于二叉树的数据结构,以实现高效的用户撤销和用户组的动态管理。同时,为了进一步提高方案的效率并实现跨企业的文件共享,该方案还允许多个授权机构联合设置系统参数并管理分布式密钥。此外,通过对用户私钥和更新密钥进行重新随机化,我们在方案中实现了抗解密密钥暴露(DKER)。我们提供了一个形式化的安全模型和一系列安全实验,表明我们的方案在选择明文攻击下是安全的。实验模拟和评估分析证明了我们方案的高效性和实用性。