Multi-authority attribute-based encryption supporting hierarchal access policy and range policy
Yuexiang Xu, Xiaolei Dong, Jiachen Shen · 2020
Attribute-based encryption (ABE) is an appropriate technique to solve the problems of data sharing in cloud computing for the reason it can offer fine-grained access control. A large amount of data usually has a hierarchal structure, which can be leveraged to improve the efficiency of ABE. For some attributes which have numerical values, it is common to make a policy to determine if a certain number is in a given range. However, it is inefficient to trivially make an OR gate consisting of all the values in the range. Moreover, as cloud computing becomes more and more widely used, ABE with single authority is no longer applicable. Thus, a multi-authority ABE scheme supporting range policy is proposed. In the proposed scheme, there is one trusted central authority and multiple attribute authorities that manage different attribute domains. The shared data can be encrypted with an integrated access policy to save storage overhead and encryption and decryption time. Extension to range policy is realized by using classic segment tree. In addition, we prove our scheme is secure against CPA under standard model and analyze the efficiency of our scheme in comparison.