TY - GEN
T1 - Verifiable Predicate-based Access Control Encryption with Dynamic Revocation
AU - Zhang, Chi
AU - Jiang, Peng
AU - Zhang, Zijian
AU - Zhu, Liehuang
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - In wireless communication, data is typically encrypted before transmission to ensure confidentiality, which complicates the implementation of access control.Predicate encryption based (PE-based) access control enables fine-grained and secure control over encrypted data. The previous PE-based access control systems only guarantee the access of the authorized receivers but not control illegal senders, and have to execute re-authorization due to its static setting. In this paper, we propose a verifiable predicate-based access control encryption supporting dynamic revocation scheme (dvPACE), which is a dynamic access control mechanism on both senders and receivers. In contrast to existing access control, dvPACE controls not only "who can access"but also "who can send". It involves an additional sanitizer to handle the cipher data and embraces multi-verification against illegal entities. To achieve efficiency and scalability, dvPACE embeds inner-product predicate encryption and borrows the idea of identity-based revocation systems. dvPACE achieves about 19ms computational cost of data access, a comparable performance over conventional mechanisms with improvements of functionalities.
AB - In wireless communication, data is typically encrypted before transmission to ensure confidentiality, which complicates the implementation of access control.Predicate encryption based (PE-based) access control enables fine-grained and secure control over encrypted data. The previous PE-based access control systems only guarantee the access of the authorized receivers but not control illegal senders, and have to execute re-authorization due to its static setting. In this paper, we propose a verifiable predicate-based access control encryption supporting dynamic revocation scheme (dvPACE), which is a dynamic access control mechanism on both senders and receivers. In contrast to existing access control, dvPACE controls not only "who can access"but also "who can send". It involves an additional sanitizer to handle the cipher data and embraces multi-verification against illegal entities. To achieve efficiency and scalability, dvPACE embeds inner-product predicate encryption and borrows the idea of identity-based revocation systems. dvPACE achieves about 19ms computational cost of data access, a comparable performance over conventional mechanisms with improvements of functionalities.
KW - Dynamic revocation
KW - access control encryption
KW - predicate encryption
KW - verifiable encryption
UR - https://www.scopus.com/pages/publications/105011364414
U2 - 10.1109/IWCMC65282.2025.11059613
DO - 10.1109/IWCMC65282.2025.11059613
M3 - Conference contribution
AN - SCOPUS:105011364414
T3 - 21st International Wireless Communications and Mobile Computing Conference, IWCMC 2025
SP - 246
EP - 251
BT - 21st International Wireless Communications and Mobile Computing Conference, IWCMC 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 21st IEEE International Wireless Communications and Mobile Computing Conference, IWCMC 2025
Y2 - 12 May 2024 through 16 May 2024
ER -