Suppr超能文献

后向兼容基于身份的加密。

Backward Compatible Identity-Based Encryption.

机构信息

Department of Cyber Security, Ewha Womans University, Seoul 03760, Republic of Korea.

出版信息

Sensors (Basel). 2023 Apr 22;23(9):4181. doi: 10.3390/s23094181.

Abstract

In this paper, we present a new identity-based encryption (IBE) system that is named Backward Compatible Identity-based Encryption (BC-IBE). Our BC-IBE is proposed to solve the problem caused by the out-of-synchronization between users' private keys and ciphertexts. Encryption systems such as revocable IBE or revocable Attribute-based Encryption (ABE) often require updating private keys to revoke users after a certain time period. However, in those schemes, an updated key can be used to decrypt the ciphertexts created only during the current time period. Once the key is updated and the previous keys are removed, the user, the owner of the updated key, will lose access to the past ciphertexts. In our paper, we propose BC-IBE that supports backward compatibility, to solve this problem. In our proposed system, user's private keys and ciphertexts can be updated periodically with time tags, and these processes can be used to revoke users who do not receive an updated key as the other revocable encryption does. However, in our proposed system, a private key newly issued to a user is backward compatible. This means that it decrypts not only the ciphertexts at the present time period but also all past ciphertexts. This implies that our proposed scheme guarantees the decryption of all encrypted data even if they are not synchronized. Compared to the existing revocable identity-based encryption system, our proposed BC-IBE has the advantage of simplifying key management and securely delegating ciphertext updates. Our proposed scheme only requires a single backward-compatible private key to decrypt all past ciphertexts created. Moreover, the ciphertext update process in our proposed scheme does not require any special privileges and does not require decryption. This means that this process can be securely delegated to a third-party server, such as a cloud server, and it prevents the potential leakage of secrets. For those reasons, BC-IBE is suitable for a system where users are more dynamic, such as the Internet-of-Things (IoT) network, or a system that regularly updates the data, like cloud data storage. In this paper, we provide the construction of BC-IBE and prove its formal security.

摘要

在本文中,我们提出了一种新的基于身份的加密(IBE)系统,名为向后兼容的基于身份的加密(BC-IBE)。我们的 BC-IBE 旨在解决由于用户私钥和密文之间的不同步而导致的问题。可撤销IBE 或可撤销基于属性的加密(ABE)等加密系统通常需要在一定时间后更新私钥以撤销用户。然而,在这些方案中,更新后的密钥只能用于解密当前时间段内创建的密文。一旦密钥更新并删除了以前的密钥,用户(更新密钥的所有者)将无法访问过去的密文。在本文中,我们提出了支持向后兼容性的 BC-IBE 来解决这个问题。在我们提出的系统中,用户的私钥和密文可以定期使用时间戳进行更新,这些过程可以用于像其他可撤销加密系统那样撤销未收到更新密钥的用户。然而,在我们提出的系统中,新颁发给用户的私钥是向后兼容的。这意味着它不仅可以解密当前时间段的密文,还可以解密所有过去的密文。这意味着我们提出的方案保证了解密所有加密数据,即使它们不同步。与现有的可撤销基于身份的加密系统相比,我们提出的 BC-IBE 具有简化密钥管理和安全委托密文更新的优势。我们提出的方案只需要一个单一的向后兼容的私钥即可解密所有过去创建的密文。此外,我们提出的方案中的密文更新过程不需要任何特殊权限,也不需要解密。这意味着这个过程可以安全地委托给第三方服务器,如云服务器,并且可以防止潜在的秘密泄露。因此,BC-IBE 适用于用户更动态的系统,例如物联网(IoT)网络,或像云数据存储一样定期更新数据的系统。在本文中,我们提供了 BC-IBE 的构造,并证明了其形式安全性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/f077/10181126/56ae010a0993/sensors-23-04181-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验