簡易檢索 / 詳目顯示

研究生: 陳文斌
Chen, Wen-Pin
論文名稱: 應用於去信任多授權機構屬性加密之雙向隱私保護資格驗證方法
A Bidirectional Privacy-Preserving Eligibility Verification Method Applied in Trustless Multi-Authority Attribute-based Encryption
指導教授: 郭耀煌
Kuo, Yau-Hwang
莊宜勲
Chuang, I-Hsun
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 人工智慧科技碩士學位學程
Graduate Program of Artificial Intelligence
論文出版年: 2026
畢業學年度: 114
語文別: 英文
論文頁數: 131
中文關鍵詞: 隱私保護去信任資格驗證屬性加密
外文關鍵詞: Privacy-preserving, Trustless, Eligibility verification, Attribute-based encryption
相關次數: 點閱:20下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 在跨組織資料共享的情境中,多授權機構屬性加密(MA-ABE)是實現細粒度(fine-grained)存取控制的關鍵技術。然而現實環境中的授權機構間通常不存在既有的信任關係,從而為資安維護帶來一系列挑戰。具體而言,在核發屬性給使用者前,授權機構必須檢驗其身份資格,但基於互不信任的前提,單一授權機構對轄下使用者的資格驗證結果顯然無法全然被他方機構採信。與此同時,各機構的資格驗證邏輯往往涉及內部機密不宜對外揭露,而機構轄下使用者的個人隱私亦不應於資格驗證過程中遭到外洩。因而,如何在此缺乏互信的環境下建立一套兼具公信力與雙向隱私保護的跨機構資格驗證機制就成為一待解難題。
    為此,本論文提出了雙向隱私保護資格驗證方法 (BPEV),旨在保護雙方隱私的情況下實現可靠的跨組織資格驗證。BPEV主要分為兩個階段:隱私保護資料綁定和安全資格評估。在第一階段,本地授權機構透過自適應承諾產生模組將使用者的資格資料封裝為可驗證承諾,並交給他方授權機構利用零知識需求驗證模組進行查驗,以確保能在不透露隱私的情況下確認其真實性。第二階段將由他方授權機構以私有函數運算技術來建構安全資格驗證邏輯,並交由本地授權機構協同完成後續驗證流程,最終將驗證結果傳回他方授權機構以完成跨組織資格驗證。藉由結合上述兩個階段,BPEV不僅能正確判定資格的合法性,更保證了跨機構協作時的雙向隱私安全。
    最後,本論文透過理論分析證明了BPEV的安全性,並藉由實現BPEV方法來驗證其正確性及可行性。實驗結果表明,在達到128-bit安全強度的雙向隱私保護情況下,BPEV僅需200ms即可完成對單一使用者的資格驗證;相較於現有僅具單向隱私保護的資格驗證方法,執行時間相差無幾。由此可見,本論文所提出的BPEV能成功在缺乏互信基礎的分散式環境中,實現兼具雙向隱私保護與高效能需求的資格驗證,為需要跨機構資格驗證的應用情境建立可靠的安全基礎。

    In cross-organizational data-sharing environments, multi-authority attribute-based encryption (MA-ABE) is a key technique for enforcing fine-grained access control. In practice, however, attribute authorities often operate without pre-established trust relationships, giving rise to a range of security challenges. Before granting attributes to a user, an authority must determine whether the user satisfies the corresponding eligibility requirements. In a mutually distrustful setting, the eligibility decision made by one authority for users under its administration cannot be fully trusted by another authority. At the same time, the eligibility-verification logic maintained by each authority may contain confidential internal information that should not be disclosed to other organizations, while users' private information must likewise remain protected throughout the verification process. Consequently, establishing a trustworthy cross-organizational eligibility-verification mechanism that also provides bidirectional privacy protection in such an environment remains a significant challenge.
    To address this challenge, this thesis proposes Bidirectional Privacy-Preserving Eligibility Verification (BPEV), a method for reliable cross-organizational eligibility verification that protects the privacy of both users and authorities. BPEV consists of two main stages: privacy-preserving data binding and secure eligibility evaluation. In the first stage, the Main Attribute Authority uses an adaptive commitment generation module to encode a user's eligibility data into verifiable commitments. The External Attribute Authority then verifies these commitments through a zero-knowledge request verification module, allowing the authenticity of the submitted data to be confirmed without revealing the underlying private information. In the second stage, the External Attribute Authority implements secure eligibility-verification logic using private function evaluation and collaborates with the Main Attribute Authority to complete the subsequent verification process. The resulting decision is then returned to the External Attribute Authority to complete the cross-organizational eligibility-verification process. By integrating these two stages, BPEV not only correctly determines whether a user satisfies the eligibility requirements but also ensures bidirectional privacy protection throughout cross-authority collaboration.
    Finally, this thesis establishes the security of BPEV through theoretical analysis and implements a BPEV prototype to evaluate its correctness and feasibility. Experimental results show that, under a 128-bit security setting, BPEV completes eligibility verification for a single user in approximately 200 ms while providing bidirectional privacy protection. Its execution time is comparable to that of existing eligibility-verification approaches that provide only one-way privacy protection. These results demonstrate that BPEV can efficiently provide eligibility verification with bidirectional privacy protection in distributed environments without pre-established mutual trust, thereby providing a reliable security foundation for applications that require cross-organizational eligibility verification.

    CHAPTER 1 INTRODUCTION 1 1.1 Background 2 1.2 Problem Description 5 1.3 Motivation 9 1.4 Contribution 13 1.5 Organization 15 CHAPTER 2 RELATED WORK 16 2.1 Attribute-Based Encryption and Multi-Authority ABE 17 2.2 Cryptographic Building Blocks 19 2.3 Existing Methods 24 CHAPTER 3 BPEV: BIDIRECTIONAL PRIVACY-PRESERVING ELIGIBILITY VERIFICATION 28 3.1 System Model 30 3.2 Threat Model 37 3.3 BPEV Framework 44 3.4 System Setup 46 3.5 Privacy-Preserving Data Binding Module 51 3.6 Zero-Knowledge Request Verification Module 59 3.7 Function-Hiding Circuit Setup Module 61 3.8 Secure Eligibility Evaluation Module 65 3.9 Commitment-Based Output Integrity Module 69 3.10 ABE Key Generation Module 71 CHAPTER 4 THEORETICAL ANALYSIS 73 4.1 Security Analysis 74 4.2 Performance Analysis 92 CHAPTER 5 EXPERIMENTS 100 5.1 Experiment Setup 100 5.2 Overall Execution Time 101 5.3 Effects of System Parameters 102 5.4 Comparison with Existing Methods 108 CHAPTER 6 CONCLUSION AND FUTURE WORK 110 6.1 Conclusion 110 6.2 Future Work 113 REFERENCES 115

    [1] A. Sahai and B. Waters, "Fuzzy identity-based encryption," in Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT), 2005, pp. 457–473.
    [2] J. Bethencourt, A. Sahai, and B. Waters, "Ciphertext-policy attribute-based encryption," in IEEE Symposium on Security and Privacy (SP), 2007, pp. 321–334.
    [3] P. Kumar, S. Kumar, and P. Alphonse, "Attribute based encryption in cloud computing: A survey, gap analysis, and future directions," Journal of Network and Computer Applications, vol. 108, pp. 37–52, 2018.
    [4] M. Chase, "Multi-authority attribute based encryption," in Theory of Cryptography Conference (TCC), 2007, pp. 515–534.
    [5] A. Lewko and B. Waters, "Decentralizing attribute-based encryption," in Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT), 2011, pp. 568–588.
    [6] S. Halevi and S. Micali, "Practical and provably-secure commitment schemes from collision-free hashing," in Annual International Cryptology Conference, 1996, pp. 201–215.
    [7] S. Goldwasser, S. Micali, and C. Rackoff, "The knowledge complexity of interactive proof-systems," Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, pp. 203–225, 2019.
    [8] A. C. Yao, "Protocols for secure computations," in 23rd Annual Symposium on Foundations of Computer Science (SFCS 1982), 1982, pp. 160–164.
    [9] M. Rosenberg, J. White, C. Garman, and I. Miers, "zk-creds: Flexible anonymous credentials from zkSNARKs and existing identity infrastructure," in IEEE Symposium on Security and Privacy (SP), 2023, pp. 790–808.
    [10] F. Baldimtsi et al., "zkLogin: Privacy-preserving blockchain authentication with existing credentials," in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 3182–3196.
    [11] R. Shi, H. Feng, Y. Yang, Y. Li, X. Li, and R. H. Deng, "Hecate: Threshold Anonymous Credentials with Private Verifiers and Issuer-Hiding," IEEE Transactions on Dependable and Secure Computing, vol. 23, no. 1, pp. 1160–1172, 2026.
    [12] V. Goyal, O. Pandey, A. Sahai, and B. Waters, "Attribute-based encryption for fine-grained access control of encrypted data," in Proceedings of the 13th ACM Conference on Computer and Communications Security (CCS), 2006, pp. 89–98.
    [13] Y. Rouselakis and B. Waters, "Efficient Statically-Secure Large-Universe Multi-Authority Attribute-Based Encryption," in Financial Cryptography and Data Security: 19th International Conference, FC 2015, San Juan, Puerto Rico, January 26-30, 2015, Revised Selected Papers, 2015, pp. 315–332.
    [14] S. Goldwasser, S. Micali, and R. L. Rivest, "A digital signature scheme secure against adaptive chosen-message attacks," SIAM Journal on Computing, vol. 17, no. 2, pp. 281–308, 1988.
    [15] D. J. Bernstein, N. Duif, T. Lange, P. Schwabe, and B.-Y. Yang, "High-speed high-security signatures," Journal of Cryptographic Engineering, vol. 2, no. 2, pp. 77–89, 2012.
    [16] A. J. Menezes, P. C. Van Oorschot, and S. A. Vanstone, Handbook of Applied Cryptography. CRC Press, 2018.
    [17] National Institute of Standards and Technology, "Secure Hash Standard (SHS)," FIPS PUB 180-4, 2012.
    [18] L. Grassi, D. Khovratovich, C. Rechberger, A. Roy, and M. Schofnegger, "Poseidon: A new hash function for zero-knowledge proof systems," in 30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 519–535.
    [19] R. C. Merkle, "A digital signature based on a conventional encryption function," in Conference on the Theory and Application of Cryptographic Techniques (CRYPTO), 1988, pp. 369–378.
    [20] J. Groth, "On the size of pairing-based non-interactive arguments," in Annual international conference on the theory and applications of cryptographic techniques, 2016, pp. 305–326.
    [21] M. Abadi and J. Feigenbaum, "Secure circuit evaluation: A protocol based on hiding information from an oracle," Journal of Cryptology, vol. 2, no. 1, pp. 1–12, 1990.
    [22] A. C.-C. Yao, "How to generate and exchange secrets," in 27th Annual Symposium on Foundations of Computer Science (SFCS 1986), 1986, pp. 162–167.
    [23] V. Kolesnikov and T. Schneider, "A practical universal circuit construction and secure evaluation of private functions," in International Conference on Financial Cryptography and Data Security, 2008, pp. 83–97.
    [24] M. O. Rabin, "How to exchange secrets with oblivious transfer," in "Cryptology ePrint Archive," 2005/187, 2005.
    [25] S. Even, O. Goldreich, and A. Lempel, "A randomized protocol for signing contracts," Communications of the ACM, vol. 28, no. 6, pp. 637–647, 1985.
    [26] D. Günther, J. Schmidt, T. Schneider, and H. Yalame, "Fluent: A tool for efficient mixed-protocol semi-private function evaluation," in Annual Computer Security Applications Conference (ACSAC), 2024, pp. 733–746.
    [27] D. Demmler, T. Schneider, and M. Zohner, "ABY-A framework for efficient mixed-protocol secure two-party computation," in Network and Distributed System Security Symposium (NDSS), 2015.
    [28] E. Barker, L. Chen, and A. Roginsky, "Recommendation for key management part 1: general (revision 5)," NIST special publication, vol. 800, p. 57, 2019.
    [29] P. Mohassel and S. Sadeghian, "How to hide circuits in MPC: An efficient framework for private function evaluation," in Annual International Conference on the Theory and Applications of Cryptographic Techniques, 2013, pp. 557–574.
    [30] V. Shoup, "Lower bounds for discrete logarithms and related problems," in International Conference on the Theory and Applications of Cryptographic Techniques, 1997, pp. 256–266.
    [31] arkworks zkSNARK ecosystem. (2022). Accessed: Jul. 5, 2026. [Online]. Available: https://arkworks.rs
    [32] FLUENT: A Framework for Efficient Mixed-Protocol Semi-Private Function Evaluation. (2024). Accessed: May 23, 2026. [Online]. Available: https://github.com/encryptogroup/FLUENT
    [33] C. Smith and A. Rusnak, "Dynamic Merkle B-tree with efficient proofs," arXiv preprint arXiv:2006.01994, 2020.
    [34] S. A. Crosby and D. S. Wallach, "Efficient data structures for tamper-evident logging," in USENIX Security Symposium, 2009, pp. 317–334.
    [35] L. Chen et al., Report on post-quantum cryptography. US Department of Commerce, National Institute of Standards and Technology, 2016.
    [36] G. Alagic et al., Status report on the fourth round of the NIST post-quantum cryptography standardization process. US Department of Commerce, National Institute of Standards and Technology …, 2025.
    [37] P. W. Shor, "Algorithms for quantum computation: discrete logarithms and factoring," in Proceedings of the 35th Annual Symposium on Foundations of Computer Science, 1994, pp. 124–134.
    [38] L. K. Grover, "A fast quantum mechanical algorithm for database search," in Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing (STOC), 1996, pp. 212–219.
    [39] P. W. Shor, "Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer," SIAM review, vol. 41, no. 2, pp. 303–332, 1999.

    QR CODE