2011 · 579 citations · 15 references
Attribute‑based encryption lets users encrypt and decrypt messages based on attributes, but ciphertext size and decryption time grow with the complexity of the access policy, limiting its use in cloud applications. This paper introduces a paradigm that largely removes this overhead for users. By storing ABE ciphertexts in the cloud and giving the cloud a single transformation key, the cloud can convert any ciphertext satisfying the user’s attributes into a constant‑size El Gamal‑style ciphertext without learning the message, and the authors provide new security definitions, constructions, implementation, and performance data. In typical settings, the approach reduces bandwidth and decryption time for users while keeping the number of transmissions unchanged.
Attribute-based encryption (ABE) is a new vision for public key encryption that allows users to encrypt and decrypt messages based on user attributes. For example, a user can create a ciphertext that can be decrypted only by other users with attributes satisfying (Faculty OR (PhD Student AND Quals Completed)). Given its expressiveness, ABE is currently being considered for many cloud storage and computing applications. However, one of the main efficiency drawbacks of ABE is that the size of the ciphertext and the time required to decrypt it grows with the complexity of the access formula. In this work, we propose a new paradigm for ABE that largely eliminates this overhead for users. Suppose that ABE ciphertexts are stored in the cloud. We show how a user can provide the cloud with a single transformation key that allows the cloud to translate any ABE ciphertext satisfied by that user's attributes into a (constant-size) El Gamal-style ciphertext, without the cloud being able to read any part of the user's messages. To precisely define and demonstrate the advantages of this approach, we provide new security definitions for both CPA and replayable CCA security with outsourcing, several new constructions, an implementation of our algorithms and detailed performance measurements. In a typical configuration, the user saves significantly on both bandwidth and decryption time, without increasing the number of transmissions.
15
Fully homomorphic encryption using ideal lattices
Craig Gentry · 2009 · 6.4K citations
Attribute-based encryption for fine-grained access control of encrypted data
Vipul Goyal, Omkant Pandey, Amit Sahai et al. · 2006 · 4.9K citations
Engineering, Information Security, Data-centric Security +19
Ciphertext-Policy Attribute-Based Encryption
John Bethencourt, Amit Sahai, Brent Waters · 2007 · 4.9K citations · Full text
Engineering, Information Security, Data-centric Security +17
Attribute-based encryption with non-monotonic access structures
Rafail Ostrovsky, Amit Sahai, Brent Waters · 2007 · 1.1K citations