A CCA-Secure Puncturable Attribute-Based Proxy Re-Encryption Scheme
Zechen Li, Guozhen Shi · IEEE Internet of Things Journal · 2025
With the rapid development of the Internet of Things (IoT) and the increase in the number of various sensor devices, there is an increasingly urgent need for cross-domain sharing of massive data in scenarios such as industrial control and smart healthcare, while the limitations of traditional encryption mechanisms in terms of inter-domain segregation and dynamic privilege management have made proxy re-encryption (PRE) technology the core solution to address the secure flow of cross-domain data. Among them, attribute-based proxy re-encryption is a promising approach. However, the existing schemes suffer from the inefficiency of inter-domain transformation and the lack of dynamic privilege revocation mechanism which is crucial for data sharing systems. Therefore, in this paper, we propose an efficient proxy re-Encryption (PRE) scheme that supports dynamic privilege management and realizes secure cross-domain conversion from Identity-Based Encryption (IBE) to Attribute-Based Encryption (ABE). In this scheme, data is first encrypted by IBE mechanism and uploaded to a semi-trusted proxy server for storage, and the data owner can authorize the proxy server to convert the ciphertext to ABE ciphertext. Notably, our scheme achieves real-time updating of keys through an attribute revocation algorithm, which ensures that historical data cannot be decrypted after authorization changes and satisfies forward security. Meanwhile, the solution builds anti-collusion mechanism by jointly generating re-encryption key by the data owner and proxy server, which effectively protects against the joint attack of malicious users and proxy server, and prevents unauthorized users from decrypting the ciphertext. In addition, the computational burden is outsourced to the proxy server, and the user only needs to perform lightweight operations, which significantly reduces the computational overhead of the data owner in data sharing. Formal security proofs show that the scheme is indistinguishable under the chosen ciphertext attack model (IND-CCA). Theoretical analysis and experimental results show that the structure is more efficient than previous schemes.