Decentralized attribute-based access control with attribute revocation and outsourced decryption

Feng Yang, Hui Cui, Jiwu Jing

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

Decentralized ciphertext-policy attribute-based encryption (CP-ABE) is considered a promising cryptographic primitive to enable fine-grained access control over encrypted data. The revocation is a necessary mechanism in real-world access control systems. However, existing revocation mechanisms in CP-ABE either are triggered periodically and cannot revoke users in a timely manner, or require a trusted third-party proxy to assist in revocation. In this work, we present a decentralized CP-ABE scheme that supports periodic attribute-level revocation as well as immediate attribute-level revocation, simultaneously. It means that once an attribute key of a user naturally expires or is identified as leaked, that attribute will be revoked and then become unavailable instantly, remaining the users' other attributes still active. Moreover, we provide optional outsourced decryption capabilities. Resource-constrained users can choose to outsource partial decryption to any third-party proxy without disclosing the underlying plaintext. The performance analysis demonstrates that our proposal is better in functionality compared with existing schemes. Our scheme is proven secure against chosen-plaintext attacks in the random oracle model.

Original languageEnglish
Title of host publication2023 15th International Conference on Computer Research and Development (ICCRD 2023)
EditorsBoshir Ahmed
Place of PublicationPiscataway NJ USA
PublisherIEEE, Institute of Electrical and Electronics Engineers
Pages246-257
Number of pages12
ISBN (Electronic)9781665487504, 9781665487498
ISBN (Print)9781665487511
DOIs
Publication statusPublished - 2023
Externally publishedYes
EventInternational Conference on Computer Research and Development (2023) - Online, China
Duration: 10 Jan 202312 Jan 2023
Conference number: 15th
https://ieeexplore.ieee.org/xpl/conhome/10079927/proceeding (Proceedings)

Conference

ConferenceInternational Conference on Computer Research and Development (2023)
Abbreviated titleICCRD 2023
Country/TerritoryChina
Period10/01/2312/01/23
Internet address

Keywords

  • Attribute-level revocation
  • Ciphertext-policy attribute-based encryption
  • Outsourced decryption

Cite this