| 研究生: |
龔俐恬 Kung, Li-Tien |
|---|---|
| 論文名稱: |
具前向安全性與常數密文長度之高效代理重加密 Efficient proxy re-encryption with forward security and constant ciphertext |
| 指導教授: |
曾一凡
Tseng, Yi-Fan |
| 口試委員: |
紀博文
Chi, Po-Wen 黃政嘉 Huang, Jheng-Jia 曾一凡 Tseng, Yi-Fan |
| 學位類別: |
碩士
Master |
| 系所名稱: |
資訊學院 - 資訊安全碩士學位學程 Master Program in Information Security |
| 論文出版年: | 2026 |
| 畢業學年度: | 114 |
| 語文別: | 英文 |
| 論文頁數: | 38 |
| 中文關鍵詞: | 代理重加密 、前向安全性 、金鑰封裝機制 、布隆過濾器 、可穿孔加密 |
| 外文關鍵詞: | Proxy Re-Encryption, Forward Security, Key Encapsulation Mechanism (KEM), Bloom Filter, Puncturable Encryption |
| 相關次數: | 點閱:27 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著雲端運算與大數據應用的普及,如何安全地進行加密資料的委託與共享已成為關鍵議題。代理重加密(Proxy Re-Encryption, PRE)允許半可信的代理伺服器將密文從委託者轉換給受託者,而無需揭露明文,有效地解決了金鑰管理與存取控制的問題。然而,傳統的 PRE 方案大多缺乏前向安全性(Forward Security);一旦使用者的長期私鑰洩漏,攻擊者將能解密該用戶過去接收過的所有歷史密文,這對需要長期機密性的應用場景構成了嚴重威脅。
針對上述問題,本論文提出了一種基於布隆過濾器(Bloom Filter)的通用前向安全代理重加密金鑰封裝機制(Forward-Secure Proxy Re-Encryption KEM)。我們提出了一個模組化的通用構造框架,將任何滿足選擇性身分安全性(IND-sID-CPA)的基於身分代理重加密(IBPRE)方案,轉換為具備前向安全性的 KEM。本方案利用布隆過濾器的機率特性來實作高效的私鑰穿孔(Key Puncturing)機制,使系統能夠以較低的儲存與運算成本實現細粒度的密鑰撤銷。
在安全性方面,我們在標準模型下定義了該方案的安全性模型,並透過嚴謹的歸約證明(Reduction Proof)論證了本方案的安全性。證明顯示,若底層的 IBPRE 方案是安全的,則本方案能抵抗選擇明文攻擊(IND-sID-CPA),且在允許攻擊者進行重加密查詢的情況下仍保持安全。分析結果表明,本方案不僅解決了密鑰洩漏後的歷史資料保護問題,同時在通訊開銷與運算效率上取得了良好的平衡,適用於安全的雲端資料共享環境。
With the proliferation of cloud computing and big data applications, secure delegation and sharing of encrypted data have become critical issues. Proxy Re-Encryption (PRE) allows a semi-trusted proxy to transform ciphertexts from a delegator to a delegatee without revealing the underlying plaintext, effectively solving key management and access control challenges. However, most traditional PRE schemes lack Forward Security. Once a user's long-term secret key is compromised, an adversary can decrypt all historical ciphertexts received by that user, posing a severe threat to applications requiring long-term confidentiality.
To address this issue, this thesis proposes a generic Forward-Secure Proxy Re-Encryption Key Encapsulation Mechanism (KEM) based on Bloom Filters. We present a modular generic construction framework that transforms any Identity-Based Proxy Re-Encryption (IBPRE) scheme satisfying selective-identity security (IND-sID-CPA) into a forward-secure KEM. Our scheme leverages the probabilistic nature of Bloom Filters to implement an efficient key puncturing mechanism, enabling the system to achieve fine-grained key revocation with low storage and computational costs.
In terms of security, we define the security model for the proposed scheme and demonstrate its security through a rigorous reduction proof in the standard model. The proof shows that if the underlying IBPRE scheme is IND-sID-CPA secure, our proposed scheme is IND-sID-CPA secure, even when the adversary is allowed to make adaptive re-encryption queries. Analysis results indicate that our scheme not only protects historical data after key compromise but also achieves a good balance between communication overhead and computational efficiency, making it suitable for secure cloud data sharing environments.
摘要 i
Abstract ii
Contents iii
List of Tables v
List of Definitions vi
List of Theorems vii
List of Notations viii
1 Introduction 1
1.1 Background 1
1.2 Contributions 5
2 Related Work 7
3 Preliminaries 9
3.1 Bloom Filters 9
3.2 Inter-Domain Identity-Based Proxy Re-Encryption 10
3.3 Puncturable Proxy Re-Encryption 12
4 Proposed Scheme 16
5 Security Analysis 20
6 Comparison 25
6.1 Evaluation of Decryption Speed 26
6.2 Evaluation of Key Size 27
7 Conclusion 29
7.1 Future Work 30
References 31
A Appendix Chapter 34
[1] M. Blaze, G. Bleumer, and M. Strauss, “Divertible protocols and atomic proxy cryptography,” in Advances in Cryptology — EUROCRYPT’98, K. Nyberg, Ed., Berlin,Heidelberg: Springer Berlin Heidelberg, 1998, pp. 127–144 (cit. pp. 1, 2).
[2] G. Ateniese, K. Fu, M. Green, and S. Hohenberger, “Improved proxy re-encryption schemes with applications to secure distributed storage,” ACM Trans. Inf. Syst. Secur.,vol. 9, no. 1, pp. 1–30, Feb. 2006 (cit. p. 2).
[3] R. Canetti and S. Hohenberger, “Chosen-ciphertext secure proxy re-encryption,” in Proceedings of the 14th ACM Conference on Computer and Communications Security, ser. CCS ’07, Alexandria, Virginia, USA: Association for Computing Machinery, 2007, pp. 185–194 (cit. p. 2).
[4] B. Libert and D. Vergnaud, “Unidirectional chosen-ciphertext secure proxy re-encryption,” in Public Key Cryptography – PKC 2008, R. Cramer, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2008, pp. 360–379 (cit. p. 2).
[5] M. Green and G. Ateniese, “Identity-based proxy re-encryption,” in Proceedings of the 5th International Conference on Applied Cryptography and Network Security, ser. ACNS ’07, Zhuhai, China: Springer-Verlag, 2007, pp. 288–306 (cit. pp. 2, 10).
[6] X. Liang, Z. Cao, H. Lin, and J. Shao, “Attribute based proxy re-encryption with delegating capabilities,” in Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, ser. ASIACCS ’09, Sydney, Australia: Association for Computing Machinery, 2009, pp. 276–286 (cit. pp. 2, 3).
[7] J. Weng, R. H. Deng, X. Ding, C.-K. Chu, and J. Lai, “Conditional proxy re-encryption secure against chosen-ciphertext attack,” in Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, ser. ASIACCS 31 ’09, Sydney, Australia: Association for Computing Machinery, 2009, pp. 322–332 (cit. p. 2).
[8] R. Canetti, S. Halevi, and J. Katz, “A forward-secure public-key encryption scheme,” in Advances in Cryptology — EUROCRYPT 2003, E. Biham, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2003, pp. 255–271 (cit. p. 2).
[9] D. Derler, S. Krenn, T. Lorünser, et al., “Revisiting proxy re-encryption: Forward secrecy, improved security, and applications,” in Public-Key Cryptography – PKC 2018, M. Abdalla and R. Dahab, Eds., Cham: Springer International Publishing, 2018, pp. 219–250 (cit. pp. 3, 5).
[10] K. Liang, L. Fang, W. Susilo, and D. S. Wong, “A ciphertext-policy attribute-based proxy re-encryption with chosen-ciphertext security,” in Proceedings of the 2013 5th International Conference on Intelligent Networking and Collaborative Systems, ser. INCOS ’13, USA: IEEE Computer Society, 2013, pp. 552–559 (cit. p. 3).
[11] M. D. Green and I. Miers, “Forward secure asynchronous messaging from puncturable encryption,” in 2015 IEEE Symposium on Security and Privacy, IEEE, 2015, pp. 305–320 (cit. pp. 4, 12).
[12] H. Xiong, L. Wang, Z. Zhou, et al., “Burn after reading: Adaptively secure puncturable identity-based proxy re-encryption scheme for securing group message,” IEEE Internet of Things Journal, vol. 9, no. 13, pp. 11 248–11 260, 2022 (cit. p. 4).
[13] S. Rüsch, D. Schürmann, R. Kapitza, and L. Wolf, “Forward secure delay-tolerant networking,” in Proceedings of the 12th Workshop on Challenged Networks, ser. CHANTS ’17, Snowbird, Utah, USA: Association for Computing Machinery, 2017, pp. 7–12 (cit. p. 4).
[14] D. Derler, K. Gellert, T. Jager, D. Slamanig, and C. Striecks, “Bloom filter encryption and applications to efficient forward-secret 0-rtt key exchange: D. derler et al.,” Journal of Cryptology, vol. 34, no. 2, p. 13, 2021 (cit. p. 5).
[15] V. Cini, S. Ramacher, D. Slamanig, and C. Striecks, “Cca-secure (puncturable) kems from encryption with non-negligible decryption errors,” in Advances in Cryptology 32 – ASIACRYPT 2020, S. Moriai and H. Wang, Eds., Cham: Springer International Publishing, 2020, pp. 159–190 (cit. pp. 5, 6, 9).
[16] Z. Li and G. Shi, “A cca-secure puncturable attribute-based proxy re-encryption scheme,” IEEE Internet of Things Journal, vol. 12, no. 22, pp. 47 679–47 690, 2025 (cit. pp. 7, 25–28).
[17] K. Worapaluk and S. Fugkeaw, “Blockchain-enabled privacy-preserving access control for ehrs sharing with optimized user and attribute revocation,” IET Information Security, vol. 2026, no. 1, p. 3 917 525, 2026. eprint: https : / / ietresearch . onlinelibrary.wiley.com/doi/pdf/10.1049/ise2/3917525 (cit. pp. 7, 25–28).
[18] Q. Zhang, S. Fu, J. Cui, et al., “Forward secure data sharing based on proxy reencryption in industrial internet of things,” IEEE Transactions on Network and Service Management, vol. 23, pp. 4042–4054, 2026 (cit. pp. 8, 25–28).
[19] B. H. Bloom, “Space/time trade-offs in hash coding with allowable errors,” Commun. ACM, vol. 13, no. 7, pp. 422–426, Jul. 1970 (cit. p. 9).
[20] Q. Tang, P. Hartel, and W. Jonker, “Inter-domain identity-based proxy re-encryption,” in Information Security and Cryptology, M. Yung, P. Liu, and D. Lin, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 332–347 (cit. pp. 10, 12, 25, 34)
全文公開日期 2031/08/24