摘要
将有密文规则的基于属性子集的属性加密方案中的想法应用到有多个认证中心的境中,实现了既支持多认证中心,又支持以属性子集的方式定制密文规则的属性加密方案.在我们的属性加密系统中,每个认证中心管理用户不同类别的属性集并且可以定制相应的密文规则进行属性加密;解密时,在每个认证中心上用户的属性集合先要通过这个认证中心上的密文规则的验证,才能够解密得到该认证中心的局部主密钥,只有得到全部局部主密钥才能解密出由系统主密钥加密的密文.同时因为在每个认证中心上支持以属性子集的方式定制密文规则,这使我们的方案能够更好支持复杂的密文规则的定制,所以我们的方案更加适合应用在有多个认证中心并且用户属性和密文规则复杂的环境.另外我们还提出了相应的安全模型并且证明方案的安全性.
In this paper we propose a scheme of attribute based encryption with attribute-sets and multi-authority which generalizes cipher policies attribute-sets based encryption(CP-ASBE) to the multi-authority scenario,adds the cipher polices attribute based system within multi-authority.In our cryptosystem,each authority center manage different kind of user′s attributes and encrypt message with cipher policies;when decryption,user′s attributes set is needs to be checked by the corresponding cipher policies on each authority server.If the attributes set is satisfied the policies,the user can get the local master key.If and only if all the local master keys are recovered,the user is able to decrypt the ciphertext which is encrypted by the system master key.At the same time our scheme can support more complex cipher policies because the attribute-sets based encryption is applied in each authority server.Furthermore our scheme can be applied into the environment with complicated user attributes,cipher policies and multi-authority center.Additional,we also propose the security model and proof it.
出处
《小型微型计算机系统》
CSCD
北大核心
2011年第12期2419-2423,共5页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目(60673046
90715037)资助
高等学校博士学科点基金项目(200801410028)资助
国家"九七三"重点基础研究发展计划项目(2007CB714205)资助
重庆自然科学基金项目(2007BA2024)资助.作者
关键词
基于属性加密
多授权中心
访问控制
秘密共享
attribute-based encryption
multi-authority
access control
secret sharing