Distributed Multi-Authority Attribute-Based Cryptography
A decentralized MA-ABE scheme addresses the inefficiencies of existing CP-ABE constructions by using LWE-based methods, enabling secure and efficient encryption and decryption for diverse access policies, particularly those represented by DNF formulas, while resisting quantum attacks.
Patent Information
- Application Number
- JP2023521063
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-10-05
- Filing Date
- 2021-10-04
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-10-04
AI Technical Summary
Existing attribute-based encryption (ABE) schemes, particularly ciphertext-policy ABE (CP-ABE), are challenging to construct securely based on the Learning With Errors (LWE) assumption, leading to inefficient ciphertext scaling for non-trivial access policies, especially when converting from key-policy ABE (KP-ABE) schemes.
A decentralized multi-authority ABE (MA-ABE) scheme is developed that supports non-trivial classes of access policies using the LWE assumption, allowing any party to act as an authority and enabling efficient encryption and decryption without a central authority, utilizing linear secret sharing schemes and LWE-based constructions.
The scheme provides secure, efficient encryption and decryption for diverse access policies, resisting collusion and quantum attacks, with scalable public and secret keys, and supports access policies captured by DNF formulas.
Smart Images

Figure 0007700851000130 
Figure 0007700851000131 
Figure 0007700851000132
Abstract
Description
Technical Field
[0001] Cross - References to Related Applications
[0002] This application claims the benefit of U.S. Provisional Application No. 63 / 087,866, filed Oct. 5, 2020, the entire contents of which are incorporated herein by reference.
[0003] Field of the Invention
[0004] The present disclosure relates to a distributed multi-authority attribute-based encryption (MA-ABE) scheme for non-trivial classes of access policies that is secure based only on the Learning With Errors (LWE) assumption under the (random oracle model) error condition.
Background Art
[0005] Background of the Invention
[0006] Attribute-based encryption (ABE) is a generalization of conventional public-key cryptography and provides fine-grained access control over encrypted data based on the recipient's credentials (or attributes). ABE has two incarnations: ciphertext-policy and key-policy. In ciphertext-policy ABE (CP-ABE), as the name implies, the ciphertext is associated with an access policy and the key is associated with attributes. In key-policy ABE (KP-ABE), the roles of the attribute set and the access policy are reversed. That is, the ciphertext is associated with attributes and the key is associated with an access policy. In either case of KP-ABE, decryption is possible only when the attributes satisfy the access policy.
[0007] Since the seminal work by Sahai and Waters and Goyal et al., ABE has become a fundamental cryptographic primitive with a long list of potential applications. Thus, designing ABE schemes naturally has attracted significant attention from the cryptographic community, and as a result, a long series of research has been done to achieve various trade-offs among expressiveness, efficiency, security, and underlying assumptions.
[0008] Most of the research bases security on cryptographic assumptions related to bilinear maps. It is very natural to seek constructions based on other assumptions. First, this is important from a conceptual perspective. More constructions not only increase confidence in the existence of the scheme, but also constructions using different assumptions often require new techniques, and as a result, the understanding of the primitive is improved. Second, this is important in light of the known attacks on group-based constructions by quantum computers. Among this general goal, currently, there is a handful of ABE schemes (beyond identity-based cryptography) that avoid bilinear maps as the underlying component.
[0009] All of these studies derive security from the hardness of the learning with errors (LWE) problem under error conditions that are currently considered difficult even for quantum computers. However, one notable fact is that existing LWE-based ABE schemes are designed in a key-policy setting. To date, the natural dual problem of constructing a CP-ABE scheme based on the LWE assumption has essentially remained completely intractable.
[0010] The only known way to implement an LWE - based CP - ABE scheme is to convert a circuit - based KP - ABE scheme to a CP - ABE scheme by using a universal circuit that represents access policies as attributes and sets of attributes as circuits. However, this conversion inherently results in a CP - ABE with parameters far from ideal for a restricted class of access policies. Specifically, for any polynomial, for s, d in the security parameter, it allows constructing a CP - ABE for access policies with a circuit of size s and depth d. Further, the size of the ciphertext generated for any access policy f is |f|·poly(λ, s, d) (starting from any KP - ABE). That is, even if the f being encrypted has a very small circuit, the CP - ABE ciphertext scales with the worst - case bounds s, d.
Summary of the Invention
Problems to be Solved by the Invention
[0011] Thus, while only assuming LWE, it is necessary to improve the above - mentioned universal - circuit - based CP - ABE construction to create a truly decentralized MA - ABE for some non - trivial classes of access policies that assume the hardness of LWE (in the random oracle model).
Means for Solving the Problems
[0012] Brief Summary of the Invention
[0013] Some embodiments of the present invention include a system, method, network device, and machine - readable medium for encrypting a message according to a multi - authority attribute - based encryption scheme, including: m for encryption iStoring an electronic message m containing bits in a computerized storage medium; Executing a global setup algorithm to generate global parameters, including selecting LWE parameters and a noise distribution, and generating a matrix B having a first column of random element data y and the rest set to 0 except for a diagonal set to 1; Executing an authority setup algorithm to generate a pair of public and private keys, including generating a first LWE matrix A, generating a second LWE matrix H, setting the public key of the authority to (A, H) and the private key to T A ; Executing a key generation algorithm, including calculating a random identifier vector t for a user by applying a cryptographic hash function to a unique identifier, calculating a vector k such that k*A = (1, t)*H, and outputting the vector k as the private key; Executing an encryption algorithm for the message m, including for each bit m i of the message m: generating a matrix X, a vector s, and a matrix V whose first column is s; generating an LWE sample c i using the LWE matrix A and the secret X; generating an LWE sample ci' using the LWE matrix H and the secret X and adding M*V*B; calculating m i ' as the most significant bit of s*y; calculating (c i , c i ') and m i XOR m i '; Storing the encrypted message in a computerized storage medium, where the encrypted message includes, for each bit m i , (c i , c i ') and mi* = m i XOR m i '.
[0014] Other embodiments of the present invention include a system, method, network device, and machine-readable medium for decrypting a message according to a multi-authority attribute-based encryption scheme, including the following: c1…c n and c1'…c n ' and m 1* …m n* Storing a message including bits representing in a computerized storage medium, the message being encrypted according to an attribute-based encryption scheme; calculating a random identifier vector t for a user by applying a cryptographic hash function to a unique identifier; obtaining a secret key k from the computerized storage medium; and executing a decryption algorithm: to decrypt the i-th bit of the message: c i *k + c i ' Calculate a linear combination of (1, t); and calculate the most significant bit of the result XOR m i* ; storing the decrypted message in the computerized storage medium.
[0015] Further embodiments include delivering the secret key through a communication network by only one authority. In further embodiments, each user is identified by a set of attributes, and the decryption ability for each encrypted message is based on a function of the attributes. Further embodiments include delivering the secret key k through a communication network by any polynomial number of independent authorities. Further embodiments include selecting a predetermined number and set of attributes for each independent authority, such that a user can decrypt the message m only if the user has at least the predetermined number of attributes from each authority.
Brief Description of the Drawings
[0016] Brief Description of the Drawings
[0017] The accompanying drawings, which are included to provide a further understanding and are incorporated in and constitute a part of this specification, illustrate the disclosed embodiments and, together with the description, serve to explain the principles of the disclosed embodiments.
[0018]
Figure 1
[0019]
Figure 2
[0020]
Figure 3
[0021]
Figure 4
DETAILED DESCRIPTION OF THE INVENTION
[0022] Detailed Description
[0023] In a standard ABE scheme, keys can only be generated and issued by a central authority. A natural extension of this concept is called multi-authority ABE (MA-ABE), which allows multiple parties to play the role of authorities (in this paper, an authority entity may be referred to as an authority, and "authority" and "authority entity" may be used interchangeably). In an MA-ABE scheme, there are multiple authorities that control different attributes, and each of them can issue a secret key to a user who owns the attributes under its control without interacting with other authorities in the system. Specifically, when given a ciphertext generated with respect to some access policy, a user who owns a set of attributes that satisfy the access policy can decrypt the ciphertext by pulling the individual secret keys obtained from the various authorities that control those attributes. Security requires the usual collusion resistance against unauthorized users, but an important difference is that now some of the attribute authorities may be corrupted and thus may collude with adversarial users.
[0024] Disclosed herein is a distributed multi-authority attribute-based encryption (MA-ABE) scheme for a non-trivial class of access policies that is secure (in the random oracle model) based only on the assumption of learning with errors (LWE) under a decryption error condition. The supported access policies are those described by disjunctive normal form (DNF) formulas. All previous constructions of MA-ABE schemes that support any non-trivial class of access policies have been proven to be secure (in the random oracle model) based on various assumptions on bilinear maps.
[0025] In the disclosed system, any party can become an authority, and there is no need for global tuning other than creating an initial set of common reference parameters. A party can simply act as a standard ABE authority by creating a public key and issuing secret keys reflecting its attributes to different users. Users can encrypt data using an arbitrary DNF formula over a chosen set of attributes. Finally, the system does not require a central authority. In terms of efficiency, when instantiating the scheme using a global bound s on the size of the access policy, the sizes of the public key, secret key, and ciphertext all grow with s.
[0026] New tools are disclosed for constructing ciphertext-policy ABE (CP-ABE) schemes using LWE. This includes a provably secure (i.e., security can be proven) CP-ABE scheme that supports access policies in NC, avoiding the conversion from a general universal circuit-based key policy to a ciphertext policy.
[0027] Also disclosed here is a new MA-ABE scheme that supports an unbounded number of attribute authorities for access policies captured by DNF formulas. This scheme is proven to be secure in the random oracle model and relies on the hardness of the LWE problem.
[0028] Embodiments include a decentralized MA-ABE scheme for access policies captured by DNF formulas under the LWE assumption. This scheme is (statically) secure against any collusion of the parties in the random oracle model, assuming the LWE assumption with a modulus-to-noise ratio smaller than an exponential function.
[0029] In the disclosed MA-ABE scheme, any party can become an authority at any time, there is no limit on the number of attribute authorities that can participate in the system, or there is no need for global tuning other than the creation of an initial set of common reference parameters created during a trusted setup.
[0030] Here, a provably secure direct CP-ABE construction that avoids the conversion from a general universal circuit-based key-policy form to a ciphertext-policy form is disclosed. In particular, the disclosed approach deviates from previous LWE-based expressive ABE constructions that are triggered by techniques of fully homomorphic encryption. In contrast, the disclosed CP-ABE is based on useful properties of linear secret sharing schemes and can be seen as an LWE version of Waters' CP-ABE scheme that relies on the decisional bilinear Diffie-Hellman assumption.
[0031] Embodiments also include a CP-ABE scheme that supports all access policies within NC 1 This scheme is selectively secure under the LWE assumption with a noise ratio modulo smaller than the exponential function. The CP-ABE scheme achieves standard selective security where the adversary has to disclose its ciphertext queries before the master public key is made public, but is allowed to adaptively make secret key queries through the security experiment. Embodiments of the CP-ABE construction further include a direct LWE-based construction of CP-ABE that includes a CP-ABE scheme for all NC 1 under the LWE assumption. The CP-ABE scheme is amenable to extension to multi-authority scenarios.
[0032] CP - ABE Scheme
[0033] Setup
[0034] For each attribute u within the system, the sample
Number
Number
Number
Number
[0035] Key Generation for Attribute Set U
[0036]
Number
Number
Number
[0037] Encryption of msg ∈ {0,1} When Matrix M is Given
[0038] Suppose ρ is a function that maps between the row indices of M and the attributes. That is, ρ(i) is the attribute associated with the i-th row in M. This procedure
Number
Number
Number
[0039] Decryption
[0040] Assume that the available attributes are eligible for decryption. Let I be the set of row indices corresponding to the available attributes,
Number
Number
Number
[0041] MA - ABE Scheme
[0042] The MA-ABE scheme is a generalization of the above scheme.
[0043] Notation
[0044] Let the underlying security parameter be represented by λ. The function negl: N → R is negligible if it is asymptotically smaller than any inverse polynomial function, that is, for any constant c > 0, for all λ > N c for negl(λ) ≤ λ -c such that an integer N c exists, it can be ignored. Let [n] = {1,..., n}.
[0045] Assume that PPT represents probabilistic polynomial-time. A certain distribution (Outer 1) For TIFF0007700851000014.tif14170, x is distributed (Outside 2) To represent that it is randomly sampled according to TIFF0007700851000015.tif13170, (Outside 3) Write it as TIFF0007700851000016.tif13170. To represent that x is sampled according to a uniform distribution over the elements of X for the set X, write x ← X. Use lowercase letters like v to represent vectors and uppercase letters like M to represent matrices. By default, assume that all vectors are row vectors. The j-th row of a matrix is denoted as M j and, similarly for the set J of row indices, for all j ∈ J, the submatrix of M consisting of the rows M j is denoted as M J For a vector v, ||v|| represents its l2 norm, and ||v|| ∞ represents its l ∞ norm.
[0046] For an integer q ≥ 2, let Z q represent the ring of integers modulo q. Represent Z q as the integers in the range (-q / 2, q / 2]. [In this paper, for simplicity, boldface fonts etc. may be written in Roman type.]
[0047] Indistinguishability
[0048] Two sequences of random variables X = {X λ} λ∈N and Y = {Y λ} λ∈N are computationally indistinguishable if there exists a negligible function negl(·) such as
Number
[0049] For two distributions D and D' on the discrete domain Ω, the statistical distance between D and D' is
Mathematics
[0050] Lattice
[0051] The m - dimensional lattice L is a discrete additive subgroup of R m . Given positive integers n, m, q and a matrix A ∈ Z q n×m ,
Mathematics
Mathematics
[0052] Discrete Gaussian
[0053] Let σ be any positive real number. The Gaussian distribution D σ with parameter σ has probability density function ρ σ (x) = exp(-π||x|| 2 / σ 2 ). For any discrete set L ⊆ R m , define ρ σ (L) = Σ x∈L ρ σ (x). The discrete Gaussian distribution D L,σ on L with parameter σ has probability density function ρ L,σ= ρ σ (x) / ρ σ is defined by (L).
[0054] Truncated Discrete Gaussian
[0055] Z with parameter σ m The truncated discrete Gaussian distribution above is
Number
Number
Number
Number
[0056] Lattice Trapdoor
[0057] A lattice with a trapdoor is a lattice indistinguishable from a randomly chosen lattice, but has a certain "trapdoor" that allows for an efficient solution to the difficult lattice problem. The trapdoor lattice sampler is denoted as LT = (TrapGen, SamplePre) and consists of two algorithms with the following syntax and properties.[[]]
[0058]
Number
[0059] [Mathematics] The pre - sampling algorithm takes as input a matrix A, a trapdoor T A , a vector u ∈ Z q n , and a parameter σ ∈ R (which determines the length of the output vector). This outputs a vector [Mathematics] .
[0060] Well - Sampledness
[0061] Furthermore, the above - mentioned sampling procedure is required to output well - sampled elements. That is, the matrix output by TrapGen should look like a uniformly random matrix, and the pre - images output by SamplePre using uniformly random vectors / matrices cannot be distinguished from vectors / matrices with entries drawn from an appropriate Gaussian distribution.
[0062] Enhanced Trapdoor Sampling
[0063] Let q: N → N, σ: N → R + be functions, and let LT=(TrapGen, SamplePre) be a trapdoor lattice sampler that satisfies the properties of q - well - sampledness of matrices and (q, σ) - well - sampledness of pre - images. We describe an improved trapdoor lattice sampling algorithm EnLT=(EnTrapGen, EnSamplePre).
[0064] [Mathematics] The trapdoor generation algorithm is [Mathematics] It generates. It appends both matrices column-wise to obtain a larger matrix A as (A1|A2), and the associated trapdoor T A is set to the combined trapdoor information T A =(T A1 ,T A2 ).
[0065]
Number
Number
[0066] Learning With Errors
[0067] For the security parameter λ ∈ N, let n:N → N, q:N → N, σ:N → R + be functions of λ. The learning with errors (LWE) assumption LWE n,q,σ under the error conditions specified by n = n(λ), q = q(λ), σ = σ(λ) states that for any PPT adversary A,
Number
Number
[0068] Given the current state of the art of the lattice problem, the LWE assumption is considered correct for any polynomial n(·) and any functions q(·), σ(·), such that for all λ ∈ N, with n = n(λ), q = q(λ), and σ = σ(λ), the following constraints are satisfied:
Number
[0069] Concept of CP - ABE for Linear Secret Sharing Scheme
[0070] For some finite field Z as q = q(λ) q A ciphertext-policy attribute-based encryption (CP-ABE) scheme for access structures captured by a linear secret sharing scheme (LSSS) over a finite field Z has four procedures with the following syntax.
[0071]
Number
Number
Number
[0072]
Number
Number
[0073]
Number
Number
[0074]
Number
Number
[0075] Concept of MA - ABE for Linear Secret Sharing Scheme
[0076] Let q = q(λ), some finite field Z qThe multi-authority attribute-based encryption (MA-ABE) system MA-ABE = (GlobalSetup, AuthSetup, KeyGen, Enc, Dec) for the access structure captured by the above linear secret sharing scheme LSSS consists of five procedures with the following syntax. (Outer 4) Represents the authority universe by TIFF0007700851000044.tif14170 (which may also be denoted as AU; the same applies to others), (Outer 5) Represents the universe of users' global identifiers by TIFF0007700851000045.tif13170. Furthermore, it is assumed that each authority controls only one attribute, so the terms "authority" and "attribute" are used interchangeably. This definition is naturally generalized to situations where each authority can potentially control any number of attributes.
[0077]
Number
[0078]
Number
Number
[0079]
Number
Number
Number
[0080]
Number
Number
[0081]
Number
Number
[0082] Linear Secret Sharing Scheme with Linear Independence
[0083] A secret sharing scheme consists of a dealer who holds the secret and a set of n parties [participants]. Informally, the dealer "divides" the secret into "shares" and distributes them among the parties. A specified subset of the "authorized" parties should be able to reconstruct the secret together, while the other parties should not be able to. The description of the set of authorized sets is called the access structure.
[0084] Access structure: The access structure of n parties associated with numbers in [n] is the set of all non-empty subsets of the parties
Number
Number
[0085] Monotone access structure (Outer 9) The secret sharing scheme for TIFF0007700851000061.tif11170 is a randomized algorithm that takes as input a secret z and outputs n shares sh1,…,sh n and is such that, for any
Number
[0086] Non - Monotonic Secret Sharing
[0087] The natural generalization of the above concept that captures (not only monotone but) all access structures is called non - monotone secret sharing. Specifically, the access structure (Outer 10) The non - monotone secret sharing scheme for TIFF0007700851000063.tif9170 is a randomized algorithm that takes as input a secret z and outputs 2n shares that can be regarded as n pairs (sh 1,0 ,sh 1,1 ),…,(sh n,0 ,sh n,1 ) and is such that
Number
[0088] The subset of all (non - monotone) secret sharing schemes for which the reconstruction procedure is a linear function of the shares is known as linear (non - monotone) secret sharing schemes.
[0089] Linear (Non - Monotonic) Secret Sharing Scheme
[0090] Let q ∈ N be a prime power and [n] be the set of parties. The access structure (Outer 11) The domain Z of secrets that realizes TIFF0007700851000065.tif10170 qA non-monotonic secret sharing scheme Π with the following property is linear in the following cases.
[0091] 1. For each share sh q of a secret z ∈ Z i,b for i ∈ [n] and b ∈ {0, 1}, forms a vector with entries in Z q .
[0092] 2. There exists a matrix
Number
Number
Number
[0093] It is well known that the above method of sharing secrets satisfies the desirable correctness and security of a non-monotonic secret sharing scheme as defined above.
Number
Number
Number
Number
Number
[0094] Correctness means that when \(S\subseteq[n]\) is permitted, the vector
Number
Number
Number
Number
[0095] A special subset of all linear secret sharing schemes is those for which the reconstruction coefficients are always binary. Such an LSSS is called a {0,1}-LSSS.
[0096] The above sharing and reconstruction methods can be directly extended to sharing vectors of dimension m ∈ N, not just scalars.
Number
[0097] Ciphertext - Policy ABE Scheme
[0098] circuit is described below. In the description of the scheme, for simplicity of presentation, it is assumed that both the encryption algorithm and the decryption algorithm receive the access policy directly in its LSSS representation. However, in an actual implementation, the encryption algorithm and the decryption algorithm instead receive the circuit representation of the access policy and can deterministically compute its LSSS representation. This is because without a circuit description of the access policy, the decryption algorithm may not be able to efficiently determine the {0,1} reconstruction coefficients required for successful decryption. 1 First, we give the parameter constraints required by our correctness and security proofs. Fix any 0 < ε < 1 / 2. For any B ∈ N,
[0099] let
Number
Number
[0100] CP - ABE Construction
[0101]
Number
[0102] The setup algorithm takes as input a security parameter λ encoded in unary, the maximum width s of the LSSS matrix supported by the scheme max = s max (λ), and the universe of attributes associated with the system (Outer 13) Include TIFF0007700851000083.tif11170. The algorithm first selects the modulus q of LWE, the dimensions n, m, and also the distributions χ lwe , χ1, χ2, χ big as described above. Next, it selects the vectors
Number
Number
Number
Number
[0103] KeyGen(MSK, U)
[0104] The key generation algorithm takes as input the master secret key MSK and the set of attributes
Number
Number
Number
Number
Number
Number
[0105] Enc(PK, msg, (M, ρ))
[0106] The encryption algorithm takes as input the public parameter PK, the message msg ∈ {0, 1} to be encrypted, and the LSSS access policy (M, ρ). Here,
Number
Number
Number
Number
Number
Number
Number
[0107] Dec(PK,CT,MSK)
[0108] Decryption takes as input the public parameter PK, a ciphertext CT that encrypts some message under some LSSS access policy (M, ρ), and a secret key SK corresponding to some subset of the attributes
Number
Number
Number
Number
[0109] Multi - Authority ABE Scheme
[0110] The MA-ABE scheme for an access structure represented by a DNF formula is shown below. This scheme is
Number
[0111] First, we give the parameter constraints required by our correctness and security proofs. Fix any 0 < ε < 1 / 2. For any B ∈ N,
Number
Number
[0112] MA - ABE Construction
[0113] GlobalSetup(1 λ ,s max )
[0114] The global setup algorithm accepts a security parameter λ encoded in unary and the maximum width s of the LSSS matrix supported by the scheme max =s max (λ). First, as described above, the modulus q of LWE, the dimensions n, m, and also the distributions χ lwe ,χ1,χ2,χ big are selected. Next, the vector
number
number
number
number
number
[0115] AuthSetup(GP,H,u)
[0116] Global parameter GP, hash function H, and authority identifier
Number
Number
[0117] KeyGen(GP,H,GID,MSK u )
[0118] The key generation algorithm takes as input the global parameter GP, the hash function H, the user's global identifier GID, and the authority's private key MSK u . First, it calculates the vector t GID =(1,H(GID))∈Z m . Next, it selects a vector
Number
Number
Number
[0119] Enc(GP,H,msg,(M,ρ),{PK u})
[0120] The encryption algorithm receives the global parameter GP, the hash function H, the message bits {0, 1} to be encrypted, the LSSS access policy (M, ρ) generated by the Lewko-Waters transform
Number
Number
Number
Number
Number
Number
[0121]
Number
[0122] Dec(GP, H, CT, GID, SK GID,u )
[0123] Decryption takes as input the global parameter GP, the hash function H, the ciphertext CT generated with respect to the LSSS access policy generated by the Lewko-Waters transformation, the user identification information GID, and the secret key {SK GID,ρ(i)} i∈I corresponding to the subset I of the row indices of the access matrix owned by that user. If (1, 0, …, 0) is not in the span of the rows of M whose indices are in the set I, decryption fails. Otherwise,
Number
Number
Number
[0124]
Number
[0125] System Implementation
[0126] Referring to FIG. 1, an exemplary system architecture for a decentralized multi-authority attribute-based encryption scheme is shown. An owner 105 of a message, such as any arbitrary data, can encrypt the message as described herein and store the generated ciphertext in cloud storage 110. Another user, shown as an accessor 115, can retrieve this ciphertext from cloud storage 110. To manage public and private keys, multiple authorities 120 can be instantiated. The authority 120 can distribute the private key to the data owner 105 and the secret key to the accessor 115. As described in this paper, a user can decrypt the ciphertext only if the user has at least a predetermined number of attributes from the required authorities.
[0127] Referring to FIG. 2, an exemplary sequence diagram for a decentralized multi-authority attribute-based encryption scheme is shown. Any data may be stored in cloud 201. The data may be uploaded to the cloud by a data owner 202. Thereafter, a user 203 may wish to retrieve the data from cloud 201. The user 203 may first view the details of the file and request a key from an authority 204. Although only a single authority 204 is shown here, multiple authorities can be instantiated and the user may communicate with multiple of those authorities.
[0128] FIGS. 3 and 4 show exemplary computer systems useful for implementing various embodiments described in this disclosure. Various embodiments can be implemented using one or more computer systems, such as computer system 500 shown in FIG. 3. One or more computer systems 500 can be used to implement any of the embodiments discussed herein, as well as combinations and sub-combinations thereof.
[0129] Computer system 500 may include one or more processors (also referred to as central processing units, processing units, CPUs), such as processor 504. Processor 504 may be connected to a communication infrastructure 506 (such as a bus, etc.).
[0130] Computer system 500 may also include user input / output devices 503, such as a monitor, keyboard, pointing device, etc., which may communicate with communication infrastructure 506 through user input / output interface 502. One or more of processors 504 may be a graphics processing unit (GPU). In certain embodiments, the GPU may be a processor that is a specialized electronic circuit designed to process math-intensive applications. The GPU may have an efficient parallel structure for parallel processing of large data blocks, such as math-intensive data common to computer graphics applications, images, videos, etc.
[0131] Computer system 500 may also include main memory 508, such as random access memory (RAM). Main memory 508 may include one or more levels of cache. Main memory 508 may store control logic (i.e., computer software, instructions, etc.) and / or data. Computer system 500 may also include one or more secondary storage devices or secondary memories 510. Secondary memory 510 may include, for example, hard disk drive 512 and / or removable storage device or removable storage drive 514. Removable storage drive 514 may interact with removable storage unit 518. Removable storage unit 518 may include a computer-usable or readable storage device storing computer software (control logic) and / or data. Removable storage drive 514 may be able to read from and / or write to removable storage unit 518.
[0132] The secondary memory 510 may include other means, devices, components, tools, or other approaches for allowing a computer program and / or other instructions and / or data to be accessed by the computer system 500. Such means, devices, components, tools, or other approaches may include, for example, a removable storage unit 522 and an interface 520. Examples of the removable storage unit 522 and the interface 520 may include a program cartridge and a cartridge interface, a removable memory chip (such as an EPROM or PROM) and an associated socket, a memory stick and a USB port, a memory card and an associated memory card slot, and / or an interface associated with other removable storage units.
[0133] The computer system 500 may further include a communication interface 524 (such as a network interface). The communication interface 524 may enable the computer system 500 to communicate and interact with any combination of external devices, external networks, external entities, etc. (collectively referred to as remote devices, networks, entities 528 individually or collectively). For example, the communication interface 524 may allow the computer system 500 to communicate with an external or remote device, network, entity 528 through a communication path 526. The communication path 526 may be wired and / or wireless (or a combination thereof) and may include any combination such as a LAN, a WAN, the Internet, etc. Control logic and / or data may be transmitted and received between the computer system 500 via the communication path 526.
[0134] Computer system 500 can be, by way of some non-limiting examples, any of a personal digital assistant (PDA), a desktop workstation, a laptop or notebook computer, a netbook, a tablet, a smartphone, a smartwatch or other wearable device, an appliance, a part of the Internet of Things, and / or an embedded system, or any combination thereof.
[0135] Computer system 500 can be a client or server computing device that accesses or hosts any application and / or data through any delivery paradigm, which includes, but is not limited to, remote or distributed cloud computing solutions; local or on-premises software (an "on-premises" cloud-based solution); a "service as" model (e.g., content as a service (CaaS), digital content as a service (DCaaS), software as a service (SaaS), managed software as a service (MSaaS), platform as a service (PaaS), desktop as a service (DaaS), framework as a service (FaaS), backend as a service (BaaS), mobile backend as a service (MBaaS), infrastructure as a service (IaaS), etc.); and / or a hybrid model that includes any combination of the foregoing examples or other services or delivery paradigms.
[0136] FIG. 4 illustrates an exemplary machine of a computer system 900, within which a set of instructions for causing the machine to perform any one or more of the operations discussed herein may be executed. In alternative implementations, the machine may be connected to other machines in a LAN, intranet, extranet, and / or the Internet (e.g., network-connected). The machine may operate as a server or a client machine in a client-server network environment, as a peer machine in a peer-to-peer (or distributed) network environment, or as a server or a client machine in a cloud computing infrastructure or environment.
[0137] The machine may be a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a cellular telephone, a web appliance, a server, a network router, a switch or bridge, a dedicated application or network security appliance or device, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while a single machine is illustrated, the term "machine" shall be construed to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.
[0138] The exemplary computer system 900 includes a processing device 902, main memory 904 (e.g., dynamic random access memory (DRAM) such as synchronous DRAM (SDRAM), read only memory (ROM), flash memory), static memory 906 (e.g., flash memory, static random access memory (SRAM)), and data storage device 918, which communicate with each other via bus 930.
[0139] The processing device 902 represents one or more processing devices such as a microprocessor, a central processing unit, etc. More specifically, the processing device can be a complex instruction set computing (CISC) microprocessor, a reduced instruction set computing (RISC) microprocessor, a very long instruction word (VLIW) microprocessor, or a processor implementing other instruction sets, or a processor implementing a combination of instruction sets. The processing device 902 can be one or more special-purpose processing devices such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), a network processor, etc. The processing device 902 is configured to execute instructions 926 for performing the operations and steps discussed herein.
[0140] The computer system 900 may further include a network interface device 908 for communicating through the network 920. The computer system 900 may include a video display device 910, an alphanumeric input device 912 (e.g., a keyboard), a cursor control device 914 (e.g., a mouse), a graphics processing device 922, a signal generation device 916 (e.g., a speaker), a graphics processing device 922, a video processing device 928, and an audio processing device 932.
[0141] The data storage device 918 may include a machine-readable medium 924 (also known as a computer-readable storage medium) on which one or more sets of instructions 926 (e.g., software instructions) embodying any one or more of the operations described herein are stored. The instructions 926 may also be present, in whole or at least in part, in the main memory 904 and / or in the processing device 902 during execution by the computer system 900, and the main memory 904 and the processing device 902 also constitute machine-readable storage media.
[0142] In one example, instruction 926 includes instructions for implementing operations and functions corresponding to the disclosed subject matter. Although machine-readable storage medium 924 is shown as a single medium in one illustrative implementation, the term "machine-readable storage medium" should be interpreted to include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store one or more sets of instruction 926. The term "machine-readable storage medium" should be interpreted to include any medium that can store or encode a set of instruction 926 for machine execution and cause a machine to perform any one or more of the operations of this disclosure. Thus, the term "machine-readable storage medium" should be interpreted to include, but not be limited to, solid state memories, optical media, and magnetic media.
[0143] Part of the detailed description is presented using algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. The operations are those requiring physical manipulation of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, and otherwise manipulated. It has proven convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc.
[0144] However, it should be noted that all of these and similar terms are related to appropriate physical quantities and are merely labels of convenience applied to such physical quantities. Unless the contrary is clearly stated, as is apparent from the above discussion, throughout this document, discussions using terms such as "identifying" or "determining" or "performing" or "executing" or "collecting" or "generating" or "transmitting" refer to actions and processes of a computer system or similar electronic computing device that manipulate data represented as physical (e.g., electronic) quantities within the registers and memories of the computer system and transform it into other data similarly represented as physical quantities within the memory or registers of the computer system or other such information storage devices.
[0145] The present disclosure also relates to an apparatus for performing the operations herein. This apparatus may comprise a computer specially constructed for the intended purposes or, alternatively, may include a computer selectively activated or reconfigured by a computer program stored in the computer. Such a computer program may be stored on a computer-readable storage medium, such as but not limited to any type of disk including floppy disks, optical disks, CD-ROMs, magneto-optical disks, read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic or optical cards, or any other type of medium suitable for storing electronic instructions. Each storage medium is coupled to the computer system bus.
[0146] The operations and figures presented in this document are not inherently related to any particular computer or other device. Various types of systems may be used with the programs according to the teachings of this document, or it may prove convenient to construct more specialized devices for performing the operations. The structures of these various systems will appear as described in this document. Further, the disclosure is not described with reference to any particular programming language. It will be understood that a variety of programming languages may be used to implement the teachings of the disclosure described herein.
[0147] The present disclosure may be provided as a computer program product or software that includes a machine-readable medium storing instructions that may be used to program a computer system (or other electronic device) to perform a process according to the present disclosure. The machine-readable medium includes any mechanism for storing information in a form readable by a machine (e.g., a computer). For example, the machine-readable (e.g., computer-readable) medium includes machine (e.g., computer) readable storage media such as read only memory ("ROM"), random access memory ("RAM"), magnetic disk storage media, optical storage media, flash memory devices, etc.
[0148] In some embodiments, a tangible, non-transitory device or article of manufacture that includes a tangible, non-transitory computer-usable or readable medium having control logic (software) stored thereon is sometimes referred to herein as a computer program product or program storage device. This includes, but is not limited to, tangible articles of manufacture embodying a computer system 500, main memory 508, secondary memory 510, and removable storage units 518 and 522, and any combination of the foregoing. When such control logic is executed by one or more data processing devices (such as computer system 500), it can cause such data processing devices to operate as described herein.
[0149] Based on the teachings contained in this disclosure, it will be apparent to those skilled in the art how to make and use embodiments of this disclosure using data processing devices, computer systems, and / or computer architectures other than those shown in FIGS. 3 and 4. In particular, the embodiments can operate using implementations of software, hardware, and / or operating systems other than those described herein.
[0150] It should be recognized that no other section, and in particular the detailed description section, is intended to be used to interpret the claims. The other sections can describe one or more exemplary embodiments, but not all, contemplated by the inventors, and thus are not intended to limit the present disclosure or the appended claims in any way.
[0151] It should be understood that this disclosure describes exemplary embodiments for exemplary fields and applications, but is not limited thereto. Other embodiments and modifications thereto are possible and within the scope and spirit of this disclosure. For example, without limiting the generality of this paragraph, the embodiments are not limited to the software, hardware, firmware, and / or entities shown in the figures described in this application. Further, the embodiments have significant utility for fields and applications beyond those described in the examples herein (whether explicitly described herein or not).
[0152] The embodiments have been described herein with the aid of functional building blocks that show specific functions and their relationships. The boundaries of these functional building blocks have been arbitrarily defined herein for convenience of explanation. Alternative boundaries can be defined as long as the specified functions and relationships (or their equivalents) are properly performed. Also, alternative embodiments can execute functional blocks, steps, operations, methods, etc. in an order different from that described herein.
[0153] References to "one embodiment", "an embodiment", "exemplary embodiment" or similar phrases in this document indicate that the described embodiment may include a particular feature, structure, or characteristic, but not all embodiments necessarily include that particular feature, structure, or characteristic. Further, such phrases do not necessarily refer to the same embodiment. Additionally, if a particular feature, structure, or characteristic is described in relation to an embodiment, incorporating such feature, structure, or characteristic into other embodiments is within the knowledge of those skilled in the art, whether or not explicitly mentioned or described in this document. Further, some embodiments may be described using the expressions "coupled" and "connected" and their derivatives. These terms are not necessarily intended to be synonyms of each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other but still cooperate or interact with each other.
[0154] The breadth and scope of the present disclosure should not be limited by any of the above exemplary embodiments, but should be defined only in accordance with the following claims and their equivalents. In the foregoing specification, implementations of the present disclosure have been described with reference to its specific exemplary implementations. It will be apparent that various modifications can be made thereto without departing from the broad spirit and scope of the present disclosure as set forth in the following claims. Thus, this specification and the drawings are to be considered in an illustrative, rather than a restrictive, sense.
Claims
1. A computer-implemented method for encrypting a message according to a multi-authority attribute-based encryption scheme, the method comprising: m bits for encryption i storing an electronic message m including i bits in a storage medium; Executing a global setup algorithm to generate global parameters, comprising: Selecting LWE parameters and a noise distribution; Generating a matrix B having a first column of data y of random elements and the rest set to 0 except for the diagonal set to 1; Executing an authority setup algorithm to generate a pair of public and private keys for the authority, comprising: Generating a first LWE matrix A; Generating a second LWE matrix H; Set the public key of the said authority to (A, H) and the private key to T A by doing so, a step; Executing a key generation algorithm, comprising: Calculating a random identifier vector t for the user by applying a cryptographic hash function to a unique identifier; Calculating a vector k such that k*A = (1,t)*H; Outputting the vector k as the private key for the user; Executing an encryption algorithm for the message m, comprising: For each bit \(m\) of message \(m\) i we have: Generating a matrix X, a vector s, and a matrix V whose first column is s; Generate an LWE sample c using the LWE matrix A and the secret X i ; Generating LWE samples ci' using the LWE matrix H and the secret X, and adding M*V*B; m i Calculate ' as the most significant bit of s*y; (c i , c i ') and m i XOR m i ' by calculation, step and; Storing the encrypted message in a storage medium, wherein the encrypted message has, for each bit m i , (c i , c i ') and m i * = m i XOR m i ', including the step Method.
2. The method of claim 1, further comprising delivering the private key through a communication network by only one authority.
3. The method of claim 1, wherein each user is identified by a set of attributes, and the decryption ability for each encrypted message is based on a function of the attributes.
4. The method of claim 3, further comprising delivering the private key k through a communication network by any polynomial number of independent authorities.
5. For each independent authority, selecting a predetermined number and a set of attributes, whereby a user can decrypt the message m only if the user has at least the predetermined number of attributes from each authority. The method according to claim 4.
6. A computer-implemented method for decrypting a message according to a multi-authority attribute-based encryption scheme, the method comprising: c 1 …c n and c 1 '…c n 'and m 1* …m n* A stage of reading a message including bits representing from a storage medium, wherein the message is encrypted according to an attribute-based encryption scheme; Calculating a random identifier vector t for the user by applying a cryptographic hash function to a unique identifier; Obtaining the private key k from the storage medium; The step of executing a decryption algorithm, comprising: For decrypting the i-th bit of the message: c i *k + c i Calculate the linear combination of '(1, t); As a result, calculate the most significant bit of XOR m i* and the step; Storing the decrypted message in the storage medium, A method.
7. The method according to claim 6, further comprising delivering the secret key k through a communication network by only one authority.
8. The method according to claim 7, wherein each user is identified by a set of attributes, and the decryption ability for each encrypted message is based on a function of the attributes.
9. The method according to claim 8, further comprising delivering the secret key k through a communication network by any polynomial number of independent authorities.
10. The method according to claim 9, further comprising, for each independent authority, selecting a predetermined number and a set of attributes, whereby a user can decrypt the message m only if the user has at least the predetermined number of attributes from each authority.
11. A computer system for encrypting a message according to a multi-authority attribute-based encryption scheme, the system comprising: m for encryption i a storage medium for storing an electronic message m including A processor, the processor performing: Executing a global setup algorithm to generate global parameters, comprising: Selecting LWE parameters and a noise distribution; Generating a matrix B having a first column of data y of random elements and the rest set to 0 except for the diagonal set to 1; Executing an authority setup algorithm to generate a pair of public and secret keys for the authority, comprising: Generating a first LWE matrix A; Generating a second LWE matrix H; Setting the public key of the permission to (A, H) and the private key to T A as a step; Executing a key generation algorithm, comprising: Calculating a random identifier vector t for the user by applying a cryptographic hash function to a unique identifier; Calculating a vector k such that k*A = (1,t)*H; Outputting the vector k as the secret key for the user; Executing an encryption algorithm for the message m, comprising: For each bit m of message m i : Generating a matrix X, a vector s, and a matrix V whose first column is s; Generate an LWE sample c using the LWE matrix A and the secret X i ; Generating LWE samples ci' using the LWE matrix H and the secret X, and adding M*V*B; m i Calculate ' as the most significant bit of s*y; (c i , c i ') and m i XOR m i ' are configured to perform steps by calculating; The memory medium is further configured to store the encrypted message in the memory medium, and the encrypted message includes, for each bit m i with respect to, (c i , c i ') and mi* = m i XOR m i ', A system.
12. The system according to claim 11, wherein the processor is further configured to deliver the secret key through a communication network by only one authority.
13. The system according to claim 11, wherein each user is identified by a set of attributes, and the decryption ability for each encrypted message is based on a function of the attributes.
14. The system according to claim 13, wherein the processor is further configured to deliver the secret key through a communication network by any polynomial number of independent authorities.
15. The system according to claim 14, wherein the processor is further configured to select a predetermined number and a set of attributes for each independent authority, whereby a user can decrypt the message m only when the user has at least the predetermined number of attributes from each authority.
16. A computer system for decrypting a message according to a multi-authority attribute-based encryption scheme, the system comprising: c 1 …c n and c 1 '…c n 'and m 1* …m n* A storage medium configured to store a message including bits representing , , , , , , , , , , , and , wherein the message is encrypted according to an attribute-based encryption scheme; a processor, the processor comprising: calculating a random identifier vector t for a user by applying a cryptographic hash function to a unique identifier; obtaining a secret key k from a computer-readable medium; executing a decryption algorithm: for decrypting the i-th bit of the message: c i *k + c i Calculate the linear combination of '(1, t); As a result, calculate the most significant bit of XOR m i* and is configured to execute the step; The storage medium is further configured to store the decrypted message. System.
17. The system according to claim 16, wherein the processor is further configured to deliver the secret key k through a communication network by only one authority.
18. The system according to claim 17, wherein each user is identified by a set of attributes, and the decryption ability for each encrypted message is based on a function of the attributes.
19. The system according to claim 18, wherein the processor is further configured to deliver the secret key through a communication network by any polynomial number of independent authorities.
20. The processor is further configured to select a set of a predetermined number and attributes for each independent permission, whereby the user can decrypt the message m only if the user has at least the predetermined number of attributes from each permission. The system according to claim 19.
Citation Information
Patent Citations
Key generation device, intermediate encryption device, consignment encryption device, decoder and their program, and personal information protection system
JP2017126851A
Anonymous key issuing for attribute-based encryption
US20100185861A1
Encryption system and key generating device
WO2016162941A1