Aug 2026· PLoS ONE· Vol 21· 0 citations· 52 references
Medicine
TL;DR
This work presents an identity-based directly revocable proxy re-encryption scheme (IBPRE-DR) based on the Learning With Errors (LWE) assumption, which is the first lattice-based identity-based proxy re-encryption scheme that integrates direct user revocation under the standard LWE assumption.
Abstract
As cloud storage becomes increasingly commonplace alongside the expansion of data sharing practices, how to achieve secure data sharing and user revocation while ensuring data confidentiality has become a key issue. Proxy re-encryption enables ciphertext originally designated for one user to be transformed by a semi-trusted proxy for another user, while identity-based encryption offers a simplified approach to key administration. However, most existing frameworks employ bilinear pairings, which suffer from susceptibility to quantum threats, and generally lack efficient revocation mechanisms. To tackle these challenges, we present an identity-based directly revocable proxy re-encryption scheme (IBPRE-DR) based on the Learning With Errors (LWE) assumption. This scheme enables data owners to directly revoke user permissions without requiring a key generation center (KGC) to frequently update user keys, supporting immediate and dynamic access control. The mechanism uses a complete subtree algorithm to achieve efficient revocation. Additionally, a dual-key mechanism distinguishes re-encryption keys from decryption keys, effectively resisting collusion attacks and further enhancing data security. Furthermore, the private key length for each user remains fixed, supporting multi-bit encryption. We present a formal definition of IBPRE-DR’s security, along with a standard-model security proof. To the best of our knowledge, this is the first lattice-based identity-based proxy re-encryption scheme that integrates direct user revocation under the standard LWE assumption. Both experimental results and theoretical analysis confirm the scheme’s effectiveness and feasibility.
As a fundamental security requirement for trustworthy cloud storage, data confidentiality has become increasingly important with the widespread adoption of cloud services. Public Key Authenticated Encryption with Keyword Search (PAEKS) enables privacy‐preserving search over encrypted data, making it well suited to se...
Rui-Jie Dong, Rang Zhou, Hui Zhang· Security and Privacy· 0 citations
The ABE-EKS framework is revisits and the proposed construction is adapted to the Type-3 pairing setting, which supports expressive access-control and keyword-search policies, Boolean keyword predicates, inequality comparisons, and trapdoor key delegation.
Koon-Ming Chan, Swee-Huay Heng, Syh-Yuan Tan et al.· Cryptography· 0 citations
These results quantify the performance distinction between the lower-latency KR-PEKS mode and the sender-authenticated searchable encryption provided by KR-PAEKS.
A privacy-preserving, secure data-sharing framework tailored for edge-cloud collaborative architectures that minimizes the computational overhead on the terminal side while safeguarding user privacy, and effectively reduces the overhead associated with user joining and revocation within the same group.
Qi-Kun Zhang, Zheng Cai, Jinbo Feng et al.· Journal of King Saud Univers...· 0 citations
A novel VMKSE scheme (VMKSE-BFF) is presented by adopting BFF, which can simultaneously support verifiability of and secure data sharing in a multi-user setting and a comparison with the existing VMKSE schemes is provided.
Yandong Su, Bing-Hang Wang, Yan-Jie Xiang et al.· Mathematics· 0 citations
By utilizing any secure symmetric-key encryption scheme as a black-box primitive, this paper demonstrates a method for constructing a symmetric-key encryption scheme that remains secure even in the presence of partial key leakage.
Reo Eriguchi, T. Iwata, Goichiro Hanaoka et al.· IACR Communications in Crypt...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.