Security Weaknesses of an "Anonymous Attribute Based Encryption" appeared in ASIACCS'13.
Payal Chaudhari, Manik Lal Das, Anish Mathuria · 2014
Attribute-based Encryption (ABE) has found enormous application in fine-grained access control of shared data, particularly in public cloud. In 2013, Zhang et al proposed a scheme called match-then-decrypt [1], where before running the decryption algorithm the user requires to perform a match operation with attribute(s) that provides the required information to identify whether a particular user is the intended recipient for the ci-phertext. As in [1], the match-then-decrypt operation saves the computa-tional cost at the receiver and the scheme supports receivers ’ anonymity. In this paper, we show that Zhang et al ’s scheme [1] does not support re-ceivers ’ anonymity. Any legitimate user or an adversary can successfully check whether an attribute is required in the matching phase, in turn, can reveal the receivers ’ identity from the attribute.