Return
Efficient Revocable Attribute-Based Encryption with Intel SGX
DOI:10.23919/cje.2025.00.287.png)
Abstract
En 中文
Cloud storage has transformed data sharing for individuals and organizations, but it also raises significant privacy concerns. Attribute-based encryption (ABE) enables fine-grained access control over encrypted data on untrusted servers, offering advantages over traditional symmetric or public-key encryption. However, with the advent of quantum computing, classical bilinear pairing-based ABE schemes face long-term security risks. Lattice-based ABE emerges as a promising post-quantum alternative, yet existing constructions suffer from large key/ciphertext sizes, inefficient Gaussian preimage sampling, and limited revocation support. To address these challenges, we propose trusted environment revocable ABE (TR-ABE), a lattice-based revocable ciphertext-policy ABE scheme explicitly designed for Intel Software Guard Extensions (SGX). By leveraging the SGX enclave, Gaussian SamplePre operations are securely outsourced while preserving confidentiality against side-channel leakage under the transparent trusted execution environment model. TR-ABE further adopts an attribute-aggregated key structure to enable efficient, resampling-free key updates, and supports efficient revocation with cryptographic binding of user identities to resist collusion. A cloud trusted execution environment framework ensures secure ciphertext updates with enclave integrity guarantees. We formally prove indistinguishability under chosen-plain-text attack security and collusion resistance under the ring learning with errors assumption in the standard model. Both theoretical analysis and experimental evaluation demonstrate significant improvements in revocation efficiency and up to 7.3 & times; performance improvement in SamplePre through secure outsourcing in Intel SGX.
Keywords:
Equations
Modeling
Security
Lattices
Algorithms
Encryption
Printing
Vectors
Tagging
Timing
Attribute-based encryption (ABE)
Access control
Efficient revocation mechanism
Trusted execution environment (TEE)
Lattice-based cryptography

