Improved CP-ABE Algorithm Based on Identity and Access Control

Dehua Zhang, Xiaopeng Yang, Ziyi Jia, Hao Li, Xiaobo Guo, Qiang Wang · 2023

To address the security vulnerabilities such as user privacy leakage and identity forgery of the traditional CP-ABE algorithm, we propose an improved CP-ABE algorithm in this paper. To achieve higher security, a hybrid signature based on ECDSA and Dilithium is introduced to provide strong non-repudiation of user identities, and a role/attribute-based access control model is designed. With this access control model, only users satisfying the access policy can access ciphertext data and thereby reducing the risk of data leakage. By performing permutation-based encryption on the attributes of the access policy, the enhanced algorithm effectively conceals the plaintext attributes, thereby enhancing the security of the access policy. The enhanced algorithm improves key generation efficiency by extracting the minimum attribute set, enhances encryption efficiency by encrypting the minimum policy satisfying the access policy, and improves decryption efficiency by having the authorization center evaluate access control attribute policies. Performance testing results demonstrate that the improved algorithm is more efficient than the traditional CP-ABE algorithm in key generation and data decryption. Security analysis indicates that compared to traditional CP-ABE algorithms, this enhanced method can effectively prevent user privacy data leakage, identity theft, and forgery attacks.

Read the paper · More papers on PaperTik