Security Weaknesses of Some Policy-Hiding Attribute-Based Encryption Schemes
نویسندگان
1 Electronics Research Institute, Sharif University of Technology, Tehran, Iran
2 Electronics Research Institute, Sharif University of Technology, Tehran, Iran
3 Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran
doi
10.22042/isecure.2025.217398چکیده
In Ciphertext-Policy Attribute-Based Encryption (CP-ABE) schemes, an access structure is sent with each ciphertext to specify the intended recipients. This design can reveal sensitive information about the encrypted data and its recipients. Moreover, it may introduce new security concerns regarding user privacy. Policy-hiding CP-ABE schemes have been proposed to address this challenge and protect user privacy. In this paper, we present the cryptanalysis of two policy-hiding CP-ABE schemes. For the first scheme, we demonstrate that it leaks attribute value information through the ciphertext. An adversary can exploit this flaw to perform an offline dictionary attack, revealing the attribute values used in the access structure, and thereby exposing the entire access structure. For the second scheme, we show that its security is compromised due to the improper establishment of the decryption key component utilized in the attribute matching phase. Data users can exploit the secret key components used in the attribute matching phase to decrypt any ciphertext, regardless of their attribute set.