Constant-Size Ciphertext Policy Comparative Attribute-Based Encryption for Mobile Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Ciphertext-Policy Attribute-Based Encryption (CP-ABE) schemes face challenges in supporting negative attributes, wildcards, and range comparisons, leading to high computational costs and unsuitability for resource-constrained devices, particularly in cloud environments where secure data access control is crucial.

Innovation Solution

The proposed Constant-size Ciphertext Policy Comparative Attribute Based Encryption (CCP-CABE) system addresses these issues by integrating attribute ranges as a single encryption parameter, using Multi-dimensional Range Derivation Functions for efficient comparisons, and enabling batch processing over attribute domains, thus reducing communication and computation overheads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional CP-ABE schemes are used to provide fine-grained access control, then security and access control capability are improved, but computational cost and system complexity increase significantly

Engineering Contradiction:
Improvesecure data access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter representation from traditional bit-wise monotone access trees to a new mathematical structure using bilinear maps and pairing-based cryptography. This allows direct evaluation of access policies without constructing complex tree structures, reducing system complexity while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical tree-structure construction and bit-wise comparison operations with a mathematical substitution using bilinear pairings. The access control evaluation is transformed from a computational tree traversal problem to a mathematical verification problem using cryptographic pairings, significantly reducing complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If CP-ABE schemes perform bitwise comparison operations in hierarchical tree structures, then access control precision is improved, but computational cost increases substantially

Engineering Contradiction:
Improveaccess control precisionVSAvoidcomputational cost
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent changes the comparison operation from bit-wise hierarchical matching to direct range comparison using mathematical functions. The access policy evaluation uses a new parameter representation that allows direct numerical comparison rather than tree traversal, reducing computational cost while maintaining precise access control.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the access control problem into independent attribute range comparisons rather than requiring complete tree structure evaluation. Each attribute can be compared independently using the new mathematical approach, reducing the overall computational burden while maintaining precise access control decisions.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If CP-ABE schemes support range comparisons and comparative attributes, then access control versatility is improved, but encryption cost grows with the number of attributes

Engineering Contradiction:
Improveaccess control versatilityVSAvoidencryption cost
Core Design Contradiction:
Adaptability or versatilityVSPower

Solution Approach 1:

The patent changes the attribute representation to support range comparisons directly through mathematical parameters. Instead of converting all attributes to bit-wise monotone structures, the system uses numerical ranges and pairing-based verification to evaluate comparative attributes efficiently, reducing encryption cost while increasing versatility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal access control mechanism that handles both exact matching and range comparisons using the same mathematical framework. The bilinear pairing-based evaluation can accommodate various attribute types (categorical, numerical, ranged) uniformly, improving versatility without proportionally increasing encryption cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If existing ABE schemes use integer comparison mechanisms for fine-grained access control, then access control precision is improved, but key size and ciphertext overhead grow linearly with the number of attributes

Engineering Contradiction:
Improveaccess control precisionVSAvoidkey size and ciphertext overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent changes the key and ciphertext structure from linear growth with attributes to constant-size structures using pairing-based cryptography. The access policy and attribute information are embedded in constant-size group elements rather than linearly scaling key materials, reducing storage overhead while maintaining precise access control.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses cryptographic copying through bilinear maps to represent attribute information compactly. Instead of storing full attribute values and comparison logic in keys and ciphertexts, the system uses constant-size group elements that encode attribute information, reducing key and ciphertext sizes while preserving access control precision.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10419404B2Enabling comparable data access control for lightweight mobile devices in clouds
Publication Date: 2019.09.17 THE ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIV OF ARIZONA
  • US10419404B2 patent drawing
  • US10419404B2 patent drawing
  • US10419404B2 patent drawing

AI summary

A new efficient framework based on a Constant-size Ciphertext Policy Comparative Attribute-Based Encryption (CCP-CABE) approach. CCP-CABE assists lightweight mobile devices and storing privacy-sensitive sensitive data into cloudbased storage by offloading major cryptography-computation overhead into the cloud without exposing data content to the cloud. CCP-CABE extends existing attribute-based data access control solutions by incorporating comparable attributes to incorporate more flexible security access control policies. CCP-CABE generates constant-size ciphertext regardless of the number of involved attributes, which is suitable for mobile devices considering their limited communication and storage capacities.