Abstract:
In recent years, in order to alleviate the pressure on the calculation of a single authorization center, multi-authorities access control schemes were proposed. But these schemes are inefficient in the revocation of user and attribute level. In this paper, a scheme was proposed based on multi-authorities and the key encryption key (KEK) tree was used to achieve revocation. In the scheme, the computation load was distributed to multi-authorities center and partial decryption was transferred to the cloud server. The security proof result shows that the scheme can resist collusion attack, and experiment results show that the scheme can effectively reduce the time consumption of ciphertext and key update in revocation process.