信息安全研究 ›› 2025, Vol. 11 ›› Issue (6): 548-.

• 学术论文 • 上一篇    下一篇

格上支持策略分割和属性撤销的CPABE方案

何苗努尔买买提·黑力力   

  1. (新疆大学数学与系统科学学院乌鲁木齐830017)
  • 出版日期:2025-06-22 发布日期:2025-06-22
  • 通讯作者: 努尔买买提·黑力力 博士,教授.主要研究方向为信息安全与密码学. nur924@sina.com
  • 作者简介:何苗 硕士.主要研究方向为云存储安全、密码基访问控制. hmiao615@sina.com 努尔买买提·黑力力 博士,教授.主要研究方向为信息安全与密码学. nur924@sina.com

A Latticebased CPABE Scheme with Policy Splitting and #br# Attribute Revocation#br#

He Miao and Nurmamat Helil   

  1. (College of Mathematics and System Science, Xinjiang University, Urumqi 830017)
  • Online:2025-06-22 Published:2025-06-22

摘要: 密文策略属性基加密(ciphertextpolicy attributebased encryption, CPABE)适合在云存储系统中提供数据的安全共享服务.然而,CPABE中属性撤销是一个棘手的问题.随着量子计算机的发展,传统的CPABE不再安全,基于格的CPABE能够抵抗量子攻击.提出一种格上支持策略分割和属性撤销的CPABE方案.该方案能够抵抗量子攻击,提供细粒度的访问控制和即时属性撤销.在属性撤销发生时,利用策略分割减少受影响的密文(块),并且通过密文更新方法减少密文更新的范围以及次数.理论分析表明该方案的计算开销在可控制的范围内.最后,在标准模型下证明了该方案是选择明文安全(INDCPA)的,并且其安全性可以归结于环上容错学习(ring learning with errors, RLWE)的困难性问题中.

关键词: 格密码, 密文策略属性基加密, 属性撤销, 策略分割, 环上容错学习

Abstract: Ciphertextpolicy attributebased encryption (CPABE) is suitable for providing secure datasharing services in the cloud storage scenario. However, attribute revocation is a challenging issue in CPABE. With the advancements in quantum computing research, traditional CPABE are no longer secure. Latticebased CPABE can resist quantum attacks. This paper proposes a latticebased CPABE scheme with policy splitting and attribute revocation. This scheme is resistant to quantum and collusion attacks. When attribute revocation occurs, this paper uses policy splitting to reduce the affected ciphertexts (blocks) and uses the lazy mode ciphertext update method to reduce the number and scope of ciphertexts that need to be updated. Theoretical analysis demonstrates that the overall storage cost of our scheme remains within a reasonable range. Finally, it is shown that, under the standard model, the scheme is proven secure against chosenplaintext attacks (CPA), and its security can be attributed to the ring learning with errors (RLWE) difficulty problem.

Key words: latticecryptography, ciphertextpolicy attributebased encryption, attribute revocation, policy splitting, ring learning with errors

中图分类号: