Fine-Grained and Traceable Key Delegation for Ciphertext-Policy Attribute-Based Encryption
Jiajie Du, Nurmamat Helil · KSII Transactions on Internet and Information Systems · 2021
Permission delegation is an important research issue in access control.It allows a user to delegate some of his permissions to others to reduce his workload, or enables others to complete some tasks on his behalf when he is unavailable to do so.As an ideal solution for controlling read access on outsourced data objects on the cloud, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has attracted much attention.Some existing CP-ABE schemes handle the read permission delegation through the delegation of the user's private key to others.Still, these schemes lack the further consideration of granularity and traceability of the permission delegation.To this end, this article proposes a flexible and fine-grained CP-ABE key delegation approach that supports white-box traceability.In this approach, the key delegator first examines the relations between the data objects, read permission thereof that he intends to delegate, and the attributes associated with the access policies of these data objects.Then he chooses a minimal attribute set from his attributes according to the principle of least privilege.He constructs the delegation key with the minimal attribute set.Thus, we can achieve the shortest delegation key and minimize the time of key delegation under the premise of guaranteeing the delegator's access control requirement.The Key Generation Center (KGC) then embeds the delegatee's identity into the key to trace the route of the delegation key.Our approach prevents the delegatee from combining his existing key with the new delegation key to access unauthorized data objects.Theoretical analysis and test results show that our approach helps the KGC transfer some of its burdensome key generation tasks to regular users (delegators) to accommodate more users.