Controlled Multi-client Functional Encryption for Flexible Access Control
摘要
In Controlled Functional Encryption (C-FE), a policy parameter is introduced during encryption to restrict how the decryptor can decrypt and compute the ciphertext, but C-FE shows certain limitations in complex scenarios involving multiple encryptors participating with their data remaining confidential from each other. To overcome these limitations and leverage the advantages of Multi-Client Functional Encryption (MCFE) and Attribute-Based Encryption (ABE), we extend C-FE, introducing a new primitive termed Controlled Multi-Client Functional Encryption for Flexible Access Control (CMCFE-FAC). This primitive introduces several key innovations: firstly, our CMCFE-FAC scheme combines MCFE to support multiple encryptors, enabling independent encryption and ensuring data privacy and security. Secondly, CMCFE-FAC combines attribute-based mechanisms to support dynamic access control, expanding traditional access control policies and enhancing their flexibility. Thirdly, we formalize the definition and security model for CMCFE-FAC, propose a CMCFE-FAC scheme tailored for the inner product function, and demonstrate the scheme’s security based on the DBDH assumption. Finally, theoretical analysis and experimental results are provided to illustrate its effectiveness and security.