1. Department of Information, Shanxi University of Finance and Economics, Taiyuan 030006, China
2. Department of Computer and Science, Taiyuan University of Technology, Taiyuan 030024, China
3. The 36th Research Institute of China Electronics Technology Corporation of Zhejiang Province, Hangzhou 314414, China
| Abstract: | The scheme of CP-ABE is widely used in data security protection in cloud outsourcing service. The architecture based on CP-ABE involves user, SP, PKG and CSP. Under this situation, PKG is trusted by default. However, in the real situation, except the default situation, there exists another scenario, where there is no SP and user communicates with PKG and CSP directly. In the above environment PKG may be untrusted. Once PKG is colluded with CSP or PKG is compromised, the adversary can get the decryption keys from PKG easily and the data preserved on CSP will be decrypted and leaked. In this paper, we first innovatively propose a scheme that can resist the attack from the aforementioned situations. The idea of the scheme is that a factor generated by the user is added to the secret key and the cipher text. The secret key is added the factor, which results that even PKG is compromised or untrusted, the secret key cannot be obtained. We apply the idea on the Li’s scheme and make it be suitable for the cloud outsourcing environment with an untrusted PKG. Finally, we prove the security of our scheme. |
| Keywords: | Outsourcing; CP-ABE; PKG; Safe Factor; CSP |
| DOI: | 10.57237/j.cst.2023.04.007 |
| 1. | Shanxi soft science research project (grant number: 2018041039-2) |
| 2. | Teaching reform project of Shanxi University of Finance and Economics (grant number: 2018226) |
| 3. | Research project of Shanxi statistical society (grant number: KY (2019) 164) |
| [1] | Sahai A, Waters B. Fuzzy Identity-Based Encryption [J]. 2005. |
| [2] | Goyal V, Pandey O, Sahai A, et al. Attribute-based encryption for fine-grained access control of encrypted data [C] // Proceedings of the 13th ACM Conference on Computer and Communications Security, CCS 2006, Alexandria, VA, USA, Ioctober 30 - November 3, 2006. ACM, 2006. |
| [3] | Bethencourt J, Sahai A, Waters B. Ciphertext-Policy Attribute-Based Encryption [C] // IEEE Symposium on Security & Privacy. IEEE, 2007. |
| [4] | Waters B. Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization [C] // Public Key Cryptography-pkc -international Conference on Practice & Theory in Public Key Cryptography. Springer, Berlin, Heidelberg, 2011. |
| [5] | Soliman H. Securing communication data in pervasive social networking based on trust with KP-ABE [J]. Computing reviews, 2022(7): 63. |
| [6] | Das S, Namasudra S. MACPABE: Multi-Authority-based CP-ABE with efficient attribute revocation for IoT-enabled healthcare infrastructure [J]. International journal of network management, 2023. |
| [7] | Green M, Hohenberger S, Waters B. Outsourcing the decryption of ABE ciphertexts [C] // Proceedings of the 20th USENIX conference on Security. USENIX Association, 2011. |
| [8] | Parno B, Raykova M, Vaikuntanathan V. How to Delegate and Verify in Public: Verifiable Computation from Attribute-Based Encryption [C] // International Conference on Theory of Cryptography. Springer-Verlag, 2012. |
| [9] | Frikken K, Atallah M, Li J. Attribute-Based Access Control with Hidden Policies and Hidden Credentials [J]. IEEE Transactions on Computers, 2006, 55(10): 1259-1270. |
| [10] | Chim T W, Yuen T H. Outsourcing Encryption of Attribute-Based Encryption with MapReduce [J]. 2012, 10.1007/978-3-642-34129-8(Chapter 17): 191-201. |
| [11] | Li J, Chen X, Li J, et al. Fine-Grained Access Control System Based on Outsourced Attribute-Based Encryption [J]. 2013. |
| [12] | F. Armknecht, J. Bohli, G. O. Karame, Z. Liu, and C. A. Reuter, “Outsourced proofs of retrievability,” in Proc. ACM SIGSAC Conf. Comput. Commun. Security, 2014, pp. 831–843. |
| [13] | Lai J, Deng R H, Pang H, et al. Verifiable Computation on Outsourced Encrypted Data [J]. 2014. |
| [14] | Song, Park. Attribute Based Proxy Re-encryption for Data Confidentiality in Cloud Computing Environments [C] // Acis/jnu International Conference on Computers. IEEE Computer Society, 2011. |
| [15] | Li Q, Ma J, Li R, et al. Large universe decentralized key-policy attribute-based encryption [J]. Security & Communication Networks, 2015, 8(3): 501-509. |
| [16] | Qi, Li, Jianfeng, et al. Large universe decentralized key-policy attribute-based encryption [J]. Security & Communication Networks, 2014. |
| [17] | Lai J, Deng R H, Li Y. Fully Secure Cipertext-Policy Hiding CP-ABE [J]. 2011. |
| [18] | Liu Z, Cao Z, Wong D S. Traceable CP-ABE: How to Trace Decryption Devices Found in the Wild [J]. IEEE Transactions on Information Forensics & Security, 2017, 10(1): 55-68. |
| [19] | Odelu V, Das A K, Rao Y S, et al. Pairing-based CP-ABE with constant-size ciphertexts and secret keys for cloud environment [J]. Computer Standards & Interfaces, 2016, 54(PT.1): 3-9. |
| [20] | Yan X, He G, Yu J, et al. Offline/Online Outsourced Attribute-Based Encryption with Partial Policy Hidden for the Internet of Things [J]. Journal of Sensors, 2020, 2020(7): 1-11. DOI: 10.1155/2020/8861114. |
| [21] | Zhou Z, Huang D. Efficient and secure data storage operations for mobile cloud computing [C] // International Conference on Network & Service Management. IEEE, 2012. |
| [22] | Lai J, Deng R H, Yang Y, et al. Adaptable Ciphertext-Policy Attribute-Based Encryption [C] // International Conference on Pairing-Based Cryptography. Springer International Publishing, 2013. |
| [23] | Hohenberger S, Waters B. Online/Offline Attribute-Based Encryption [C] // International Workshop on Public Key Cryptography. Springer, Berlin, Heidelberg, 2014. |
| [24] | Ma H, Zhang R, Wan Z, et al. Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing [J]. IEEE Transactions on Dependable & Secure Computing, 2017, 14(6): 679-692. |
| [25] | Li J, Li X, Wang L, et al. Fuzzy encryption in cloud computation: efficient verifiable outsourced attribute-based encryption [J]. Soft Computing, 2017. |
| [26] | Li J, Wang Y, Zhang Y, et al. Full Verifiability for Outsourced Decryption in Attribute Based Encryption [J]. IEEE Transactions on Services Computing, 2020, 1939: 1. |
| [27] | Guo R, Yang G, Shi H, et al. O-R-CP-ABE: An Efficient and Revocable Attribute-Based Encryption Scheme in the Cloud-Assisted IoMT System [J]. IEEE Internet of Things Journal, 2021, PP (99): 1. |
| [28] | Zheng, F, Peng, XG, Li, ZD, et al. An Efficient User's Attribute Revocation Scheme Suitable for Data Outsourcing in Cloud Storage [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2022. |
| [29] | Sowjanya K, Mou D, Ray S. A lightweight key management scheme for key-escrow-free ECC-based CP-ABE for IoT healthcare systems [J]. Journal of Systems Architecture, 2021, 117(2): 102108. |
| [30] | Zhang, Z., W. Zhang, and Z. Qin. "A partially hidden policy CP-ABE scheme against attribute values guessing attacks with online privacy-protective decryption testing in IoT assisted cloud computing." Future Generation Computer Systems 123(2021). |
| [31] | Sarma R, Kumar C, Barbhuiya F A. PAC-FIT: An efficient privacy preserving access control scheme for fog-enabled IoT [J]. Sustainable Computing: Informatics and Systems, 2021, 30(2): 100527. |
| [32] | Rs A, Cka B, Fab A. MACFI: A multi-authority access control scheme with efficient ciphertext and secret key size for fog-enhanced IoT [J]. 2021. |
| [33] | Yang L, Li C, Cheng Y, et al. Achieving privacy-preserving sensitive attributes for large universe based on private set intersection [J]. Information Sciences, 2022, 582: 529-546. |
| [34] | Ning J, Cao Z, Dong X, et al. CryptCloud: Secure and Expressive Data Access Control for Cloud Storage [J]. IEEE Transactions on Services Computing, 2021, 14(1): 111-124. |