Attacking Two Pairing-Free Ciphertext-Policy Attribute-Based Encryption Schemes

نویسندگان

1 Electronics Research Institute, Sharif University of Tech., Tehran, Iran

2 Information Systems and Security Lab. (ISSL), Department of Electrical Engineering, Sharif University of Tech., Tehran, Iran

3 Information Systems and Security Lab. (ISSL), Department of Electrical Engineering, Sharif University of Tech., Tehran, Iran

doi
10.22042/isecure.2025.216447
چکیده

Attribute-based encryption (ABE) is one of the recommended tools to secure real systems like the Internet of Things (IoT). Almost all the ABE schemes utilize bilinear map operations, known as pairings. The challenge with these schemes is that performing pairings results in high computation costs and IoT devices are typically resource-constrained, so, efficient pairing-free ABE schemes have been proposed to solve this issue. These schemes utilize classical cryptographic operations instead of heavy bilinear pairings. Recently, two pairing-free ciphertext-policy attribute-based encryption schemes have been proposed (by Das et al. and Sowjanya et al.). According to their claims, their schemes are secure against collusion attacks and provide indistinguishability in a selective-set security model. The first scheme also has been claimed to be secure against forgery attacks. In this paper, we show that the first scheme is vulnerable to ciphertext-only, collusion between four or more data users with specific features, and forgery attacks. We also show that the second scheme is vulnerable to a key recovery attack, which can lead to a collusion attack. So, even though they are highly efficient, they have some security vulnerabilities that can violate the claims of the authors.