Outsourcing the decryption of ABE ciphertexts

Matthew Green, Susan Hohenberger, Brent Waters

2011 · 579 citations · 15 references

TL;DR

Attribute‑based encryption lets users encrypt and decrypt messages based on attributes, but ciphertext size and decryption time grow with the complexity of the access policy, limiting its use in cloud applications. This paper introduces a paradigm that largely removes this overhead for users. By storing ABE ciphertexts in the cloud and giving the cloud a single transformation key, the cloud can convert any ciphertext satisfying the user’s attributes into a constant‑size El Gamal‑style ciphertext without learning the message, and the authors provide new security definitions, constructions, implementation, and performance data. In typical settings, the approach reduces bandwidth and decryption time for users while keeping the number of transmissions unchanged.

Abstract

Attribute-based encryption (ABE) is a new vision for public key encryption that allows users to encrypt and decrypt messages based on user attributes. For example, a user can create a ciphertext that can be decrypted only by other users with attributes satisfying (Faculty OR (PhD Student AND Quals Completed)). Given its expressiveness, ABE is currently being considered for many cloud storage and computing applications. However, one of the main efficiency drawbacks of ABE is that the size of the ciphertext and the time required to decrypt it grows with the complexity of the access formula. In this work, we propose a new paradigm for ABE that largely eliminates this overhead for users. Suppose that ABE ciphertexts are stored in the cloud. We show how a user can provide the cloud with a single transformation key that allows the cloud to translate any ABE ciphertext satisfied by that user's attributes into a (constant-size) El Gamal-style ciphertext, without the cloud being able to read any part of the user's messages. To precisely define and demonstrate the advantages of this approach, we provide new security definitions for both CPA and replayable CCA security with outsourcing, several new constructions, an implementation of our algorithms and detailed performance measurements. In a typical configuration, the user saves significantly on both bandwidth and decryption time, without increasing the number of transmissions.

References

15