On the security of the hierarchical attribute based encryption scheme proposed by Wang et al

Mohammad Ali,Javad Mohajeri,Mohammad-Reza Sadeghi
DOI: https://doi.org/10.48550/arXiv.1810.05864
2018-10-13
Abstract:Ciphertext-policy hierarchical attribute-based encryption (CP-HABE) is a promising cryptographic primitive for enforcing the fine-grained access control with scalable key delegation and user revocation mechanisms on the outsourced encrypted data in a cloud. Wang et al. (2011) proposed the first CP-HABE scheme and showed that the scheme is semantically secure in the random oracle model [4, 5]. Due to some weakness in its key delegation mechanism, by presenting two attacks, we demonstrate the scheme does not offer any confidentiality and fine-grained access control. In this way, anyone who has just one attribute can recover any outsourced encrypted data in the cloud.
Cryptography and Security
What problem does this paper attempt to address?