Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based Encryption
Xiaoguo Li, Guomin Yang, Tao Xiang, Shengmin Xu, Bowen Zhao, HweeHwa Pang, Robert H. Deng
摘要
As an advanced one-to-many public key encryption system, attribute-based encryption (ABE) is widely believed to be a promising technology for achieving flexible and fine-grained access control of encrypted data on untrusted storage servers (e.g., public cloud servers). However, user revocation in ABE is a critical but challenging problem, and designing efficient revocable ABE has been an active research topic in the past decade. Almost all the existing revocable ABE schemes incorporate a timestamp in the encryption algorithm such that revoked users cannot decrypt ciphertexts generated in future time intervals. To prevent revoked users from decrypting past ciphertexts, the storage server needs to perform a process called ciphertext delegation (Sahai et al., CRYPTO’12) that periodically updates the timestamp for all ciphertexts. As the number of ciphertexts could be huge in a storage system, ciphertext delegation could pose a huge computation overhead to the server.Motivated by the popularity of commodity Trusted Execution Environment (TEE) technologies, this paper initiates the study on hardware-based revocable ABE (HR-ABE) to eliminate the (unscalable) ciphertext delegation and prevent collusion attacks between an untrusted storage server and revoked users. We formalize this new notion and present an efficient HR-ABE construction that also supports outsourced decryption for resource-constrained data users. Furthermore, HR-ABE is also designed to address the potential secret leakage problem suffered by TEE (e.g., due to side-channel attacks) so that the leakage of secrets possessed by TEE does not lead to leakage of user data. We prove HR-ABE’s security formally and benchmark its performance experimentally.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Registered Attribute-Based EncryptionSusan Hohenberger, George Lu, Brent Waters, David J. WuEUROCRYPT 2023 · 被引用 83 次
- Broadcast, Trace and Revoke with Optimal Parameters from Polynomial HardnessShweta Agrawal, Simran Kumari, Anshu Yadav, Shota YamadaEUROCRYPT 2023 · 被引用 7 次
- SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value StoresYanjing Ren, Jingwei Li, Patrick LeeVLDB 2026
- On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the CloudWilliam C. Garrison III, Adam Shull, Steven A. Myers, Adam J. LeeS&P 2016 · 被引用 77 次
- ISABELLA: Improving Structures of Attribute-Based Encryption Leveraging Linear AlgebraDoreen Riepel, Marloes Venema, Tanya VermaCCS 2024 · 被引用 1 次
