• DocumentCode
    2756251
  • Title

    Ciphertext-Policy Attribute-Based Encryption

  • Author

    Bethencourt, John ; Sahai, Amit ; Waters, Brent

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA
  • fYear
    2007
  • fDate
    20-23 May 2007
  • Firstpage
    321
  • Lastpage
    334
  • Abstract
    In several distributed systems a user should only be able to access data if a user posses a certain set of credentials or attributes. Currently, the only method for enforcing such policies is to employ a trusted server to store the data and mediate access control. However, if any server storing the data is compromised, then the confidentiality of the data will be compromised. In this paper we present a system for realizing complex access control on encrypted data that we call ciphertext-policy attribute-based encryption. By using our techniques encrypted data can be kept confidential even if the storage server is untrusted; moreover, our methods are secure against collusion attacks. Previous attribute-based encryption systems used attributes to describe the encrypted data and built policies into user´s keys; while in our system attributes are used to describe a user´s credentials, and a party encrypting data determines a policy for who can decrypt. Thus, our methods are conceptually closer to traditional access control methods such as role-based access control (RBAC). In addition, we provide an implementation of our system and give performance measurements.
  • Keywords
    authorisation; cryptography; distributed processing; storage management; ciphertext-policy attribute-based encryption; collusion attack; data confidentiality; distributed system; policy enforcement; role-based access control; trusted storage server; Access control; Certification; Cryptography; Data security; File servers; Measurement; Monitoring; Personnel; Public key; Secure storage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2007. SP '07. IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2848-1
  • Type

    conf

  • DOI
    10.1109/SP.2007.11
  • Filename
    4223236