Attribute-Based Encryption and Access Control (Data-Enabled Engineering)
Book information
Description
This book covers a broader scope of Attribute-Based Encryption (ABE), from the background knowledge, to specific constructions, theoretic proofs, and applications. The goal is to provide in-depth knowledge usable for college students and researchers who want to have a comprehensive understanding of ABE schemes and novel ABE-enabled research and applications. The specific focus is to present the development of using new ABE features such as group-based access, ID-based revocation, and attributes management functions such as delegation, federation, and interoperability. These new capabilities can build a new ABE-based Attribute-Based Access Control (ABAC) solution that can incorporate data access policies and control into ciphertext. This book is also ideal for IT companies to provide them with the most recent technologies and research on how to implement data access control models for mobile and data-centric applications, where data access control does not need to rely on a fixed access control infrastructure. It’s also of interested to those working in security, to enable them to have the most recent developments in data access control such as ICN and Blockchain technologies. Features Covers cryptographic background knowledge for ABE and ABAC Features various ABE constructions to achieve integrated access control capabilities Offers a comprehensive coverage of ABE-based ABAC Provides ABE applications with real-world examples Advances the ABE research to support new mobile and data-centric applications Cover Half Title Series Page Title Page Copyright Page Dedication Contents Preface Authors Contributors Part I: Foundations of Attribute-Based Encryption for Attribute-Based Access Control Chapter 1: Foundations of Attribute-Based Encryption 1.1 Attribute-Based Access Control—An ABE Approach 1.1.1 Motivation of ABE-Based Attribute-Based Access Control 1.1.2 Potentials and Issues of ABAC 1.2 Mathematical Background 1.2.1 Group and Cyclic Group 1.2.2 Prime-Order Bilinear Pairing 1.2.3 Composite-Order Bilinear Pairing 1.3 Basic Construction Components of ABE 1.3.1 Access Structure 1.3.2 Linear Secret-Sharing Scheme 1.3.3 Conversion Algorithm 1.3.4 Access Structure Example 1.3.5 Key-Policy Attribute-Based Encryption 1.3.6 Ciphertext-Policy Attribute-Based Encryption 1.4 Notations 1.5 Summary Chapter 2: Comparable Attribute-based Encryption 2.1 CCP-CABE Application Framework 2.2 Definition of Attribute Range and Problem Formulation 2.3 Composite Order Bilinear Map 2.4 Multi-Dimensional Range Derivation Function 2.5 CCP-CABE Overview 2.6 Security Model 2.7 Construction 2.7.1 System Setup (Setup) 2.7.2 Key Generation (KeyGen) 2.7.3 Encryption Delegation (EncDelegate) 2.7.4 Encryption (Encrypt) 2.7.5 Decryption Delegation (DecDelegate) 2.7.6 Decryption (Decrypt) 2.7.7 Application Scenarios 2.8 Extended Construction 2.8.1 ECCP-CABE Encryption 2.8.2 ECCP-CABE Decryption 2.9 Performance Evaluation 2.9.1 Complexity Analysis 2.9.2 Experiment 2.10 Security Analysis 2.10.1 Security for MRDF 2.10.2 Security for Key Collusion Attacks 2.10.3 Security for Chosen Delegation Key and Ciphertext Attacks 2.11 Summary Chapter 3: Privacy-Preserving Attribute-Based Encryption 3.1 Introduction 3.2 Related Works 3.3 Models 3.3.1 Attributes, Policy, and Anonymity 3.3.2 Broadcast with Attribute-Based Encryption 3.3.3 Bilinear Maps 3.3.4 Complexity Assumption 3.4 PP-CP-ABE Construction 3.4.1 PP-CP-ABE Construction Overview 3.4.2 Setup 3.4.3 Key Generation 3.4.4 Encryption 3.4.5 Decryption 3.4.6 Security Analysis 3.5 Privacy-Preserving Attribute-Based Broadcast Encryption 3.5.1 PP-AB-BE Setup 3.5.2 Broadcast Encryption 3.5.3 Information Theoretical Optimality 3.6 System Performance Assessment 3.6.1 Communication Overhead 3.6.2 Storage Overhead 3.6.3 Computation Overhead 3.7 Summary Chapter 4: Identity Revocable CP-ABE 4.1 Introduction 4.1.1 Research Contribution 4.2 Flexible Group Construction 4.3 Why Is the Two-Step ID-Revocable CP-ABE Approach NOT Secure? 4.4 Syntax and Security Model 4.4.1 Syntax of IR-CP-ABE 4.4.2 Security Model 4.4.3 Assumptions 4.5 Scheme Construction 4.5.1 One-ID Revocation for CP-ABE Scheme (OIDR-CP-ABE) 4.5.2 Multiple-ID Revocation for CP-ABE Scheme (MIDR-CP-ABE) 4.6 Delegation 4.7 Performance Evaluation 4.7.1 Computation, Storage, and Communication Complexity Analysis 4.7.2 Implementation and Testing Results 4.7.3 The Advantage of IR-CP-ABE in Secure Group Construction 4.8 Summary Chapter 5: Extended Identity-Revocable CP-ABE 5.1 Introduction 5.2 System and Models 5.2.1 EIR-CP-ABE Trust Framework 5.2.2 Security Model 5.3 EIR-CP-ABE Protocols 5.3.1 Global Setup 5.3.2 Federated Setup and Key Generation Protocol 5.3.3 Key Generation Delegation Protocol 5.3.4 Interoperability within and between Organizations 5.3.5 Identity-Revocable Data Distribution and Access Protocol 5.4 Analysis and Evaluation 5.4.1 Complexity Analysis 5.4.2 Security Analysis 5.5 Summary Chapter 6: Search over ABE-Protected Data 6.1 Introduction 6.2 Related Works 6.2.1 S/M Searchable Encryption 6.2.2 M/M Searchable Encryption 6.2.3 Attribute-Based Encryption 6.3 System and Models 6.3.1 Threat Model 6.3.2 Design Goals 6.4 Online/Offline Attribute-Based Keyword Search 6.4.1 Notations and Preliminaries 6.4.2 Definitions and Security 6.5 ABKS Schemes with Online/Offline Encryption and Trapdoor Generation 6.5.1 Online/Offline KP-ABKS 6.5.2 Online/Offline CP-ABKS 6.6 Security Analysis 6.6.1 Definition for ABKS 6.6.2 Selective Security against Chosen-Keyword Attack 6.6.3 Keyword Secrecy 6.6.4 Cryptographic Assumption 6.6.5 Security of ZXA 6.6.6 Security of OO-ABKS 6.7 Performance Evaluation 6.8 Summary Chapter 7: Attribute-Based Signature with Policy-and-Endorsement Mechanisms 7.1 Introduction 7.2 Related Works 7.3 Preliminaries 7.3.1 Attribute-Based Cryptosystem 7.3.2 Access Policy and Attribute Tree 7.3.3 Correctness and Security Definitions 7.4 The Construction for PE-ABS 7.4.1 Bilinear Group System 7.4.2 Hashing Functions 7.4.3 Policy-Endorsing Attribute-Based Signature 7.4.4 Disperse and Aggregate Algorithms 7.5 Security Proof of PE-ABS Scheme 7.5.1 Selfless Anonymity Security 7.5.2 Existential Unforgeability under Chosen Message Attacks 7.6 Performance Analysis 7.7 Summary Part II: Applications of Attribute-Based Encryption Chapter 8: Efficient Key Management for Secure Multicast Communication 8.1 Introduction 8.2 Related Works 8.3 System Models and Background 8.3.1 Notations 8.3.2 Communication Model 8.3.3 Bilinear Pairing 8.3.4 Attack Models 8.4 Constructions of OGK 8.4.1 ID and Bit-Assignment 8.4.2 Group Setup 8.4.3 GM Joining and Key Generation 8.4.4 Encryption and Decryption 8.4.5 Encryption for Subgroups of GMs 8.4.6 GM Leaving 8.5 Information Theoretical Storage-Communication-Optimality 8.5.1 Optimal Storage 8.5.2 Storage-Communication-Optimality 8.6 Implementation of OGK 8.6.1 Parameters 8.6.2 Further Reducing Ciphertext Size 8.7 Performance Analysis 8.7.1 Communication Overhead 8.7.2 Storage Overhead 8.7.3 Computation Overhead 8.8 Security Proof of OGK Scheme 8.9 Summary Chapter 9: Gradual Identity Exposure Using Attribute-Based Encryption 9.1 Introduction 9.2 Related Works and Background 9.3 System and Models 9.3.1 Concepts 9.3.2 Communication Model 9.3.3 Attack Model 9.4 Constructions of Gradual Identity Exposure 9.4.1 Construction of AND Gate Chain 9.4.2 System Setup 9.4.3 Key Generation 9.4.4 Encryption and Decryption of the AND Chain 9.5 Anonymity Evaluation Models and Security Analysis of GIE 9.5.1 Security Analysis 9.6 Performance Evaluation of GIE 9.6.1 Communication Overhead 9.6.2 Computation Overhead 9.7 Summary Chapter 10: ABE for IoT and Mobile Cloud Computing 10.1 Introduction 10.2 Related Works 10.3 System and Models 10.3.1 Notations 10.3.2 Overview of PP-CP-ABE Scheme 10.3.3 Attacking Models 10.3.4 Access Policy Tree 10.3.5 Definitions Used for Security Proofs 10.4 Privacy Preserving CP-ABE 10.4.1 Overview of the Construction 10.4.2 System Setup and Key Generation 10.4.3 PP-CP-ABE Encryption 10.4.4 Offloading Decryption 10.5 Attribute-Based Data Storage 10.5.1 Data Management Overview 10.5.2 Setup 10.5.3 Upload New Files 10.5.4 Data Updates 10.6 Performance Evaluation 10.6.1 Security Assessments 10.6.2 Performance Evaluation 10.7 Summary Chapter 11: ABE-Based Content Access Control for ICN 11.1 Introduction 11.2 Related Works 11.2.1 ICN Solutions 11.2.2 ABE Schemes 11.3 System and Models 11.3.1 Application Scenarios 11.3.2 Attribute-Based Naming and Access Control 11.3.3 Comparable Attributes and Attribute Rankings 11.3.4 An Illustrative Example 11.3.5 Attack Model 11.3.6 Preliminaries of ABE 11.4 ABE-Based ICN-Naming Scheme 11.4.1 Creating a Content 11.4.2 ABE-Based Naming Scheme 11.4.3 Attribute Rankings 11.4.4 Apply ABE-Based Naming Scheme in ICN 11.5 Performance Analysis and Evaluation 11.5.1 Evaluation of the Naming Scheme 11.5.2 Real-World Implementation 11.5.3 Complexity Comparison 11.6 Security Analysis 11.6.1 ABE Security Model 11.6.2 Security Proof 11.7 Summary Chapter 12: ABE for Vehicular Network Security Policy Enforcement 12.1 Introduction 12.2 Related Works 12.3 AVN-SPE System and Models 12.3.1 Network Model 12.3.2 Policy Tree Formation 12.3.3 ABE Protocols 12.3.4 Attack Model 12.4 Descriptions of AVN-SPE 12.4.1 Phase I: Group Key Distribution 12.4.2 Phase II: Group and Sub-Group Communication 12.4.3 AVN-SPE Operation Optimizations 12.5 Performance Assessments 12.5.1 Performance Evaluation Setup 12.5.2 Computation Overhead 12.5.3 Communication Overhead 12.5.4 Security Analysis 12.6 Summary Chapter 13: Using ABE to Secure Blockchain Transaction Data 13.1 Introduction 13.2 System and Models 13.2.1 Blockchain Technology for Supply Chain 13.2.2 Smart Contract 13.2.3 ABE-Enabled ABAC 13.2.4 Security Model 13.3 PoP System Models 13.3.1 Access System Construction 13.3.2 Privacy-Preserving Messaging Protocol (PPMP) 13.3.3 Smart Contract Protocols 13.3.4 Policy-Based Data Privacy Protection 13.4 PoP Operation and Performance Analysis 13.4.1 Complexity Analysis 13.4.2 Computation Evaluation 13.4.3 Security Analysis 13.4.4 Comparative Study 13.5 Summary References Index
Similar books
Measuring Second Language Pragmatic Competence: A Psycholinguistic Perspective (Second Language Acquisition, 166)
2024 · PDF
Atomically Precise Nanoclusters
2020 · PDF
Atomically Precise Nanoclusters
2020 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF