Publications
Article type
Sort:
Open Access Article Issue
LUAR: Lightweight and Universal Attribute Revocation Mechanism with SGX Assistance towards Applicable ABE Systems
Computers, Materials & Continua 2026, 86(3): 69
Published: 12 January 2026
Abstract PDF (2.8 MB) Collect
Downloads:0

Attribute-Based Encryption (ABE) has emerged as a fundamental access control mechanism in data sharing, enabling data owners to define flexible access policies. A critical aspect of ABE is key revocation, which plays a pivotal role in maintaining security. However, existing key revocation mechanisms face two major challenges: (1) High overhead due to ciphertext and key updates, primarily stemming from the reliance on revocation lists during attribute revocation, which increases computation and communication costs. (2) Limited universality, as many attribute revocation mechanisms are tailored to specific ABE constructions, restricting their broader applicability. To address these challenges, we propose LUAR (Lightweight and Universal Attribute Revocation), a novel revocation mechanism that leverages Intel Software Guard Extensions (SGX) while minimizing its inherent limitations. Given SGX’s constrained memory ( 90 MB in a personal computer) and susceptibility to side-channel attacks, we carefully manage its usage to reduce reliance while mitigating potential collusion risks between cloud service providers and users. To evaluate LUAR’s lightweight and universality, we integrate it with the classic BSW07 scheme, which can be seamlessly replaced with other ABE constructions. Experimental results demonstrate that LUAR enables secure attribute revocation with low computation and communication overhead. The processing time within the SGX environment remains stable at approximately 55 ms, regardless of the complexity of access policies, ensuring no additional storage or computational burden on SGX. Compared to the Hardware-based Revocable Attribute-Based Encryption (HR-ABE) scheme (IEEE S&P 2024), LUAR incurs a slightly higher computational cost within SGX; however, the overall time from initiating a data request to obtaining plaintext is shorter. As access policies grow more complex, LUAR’s advantages become increasingly evident, showcasing its superior efficiency and broader applicability.

Open Access Article Issue
Heterogeneous User Authentication and Key Establishment Protocol for Client-Server Environment
Computers, Materials & Continua 2026, 87(1): 23
Published: 10 February 2026
Abstract PDF (1.1 MB) Collect
Downloads:0

The ubiquitous adoption of mobile devices as essential platforms for sensitive data transmission has heightened the demand for secure client-server communication. Although various authentication and key agreement protocols have been developed, current approaches are constrained by homogeneous cryptosystem frameworks, namely public key infrastructure (PKI), identity-based cryptography (IBC), or certificateless cryptography (CLC), each presenting limitations in client-server architectures. Specifically, PKI incurs certificate management overhead, IBC introduces key escrow risks, and CLC encounters cross-system interoperability challenges. To overcome these shortcomings, this study introduces a heterogeneous signcryption-based authentication and key agreement protocol that synergistically integrates IBC for client operations (eliminating PKI’s certificate dependency) with CLC for server implementation (mitigating IBC’s key escrow issue while preserving efficiency). Rigorous security analysis under the mBR (modified Bellare-Rogaway) model confirms the protocol’s resistance to adaptive chosen-ciphertext attacks. Quantitative comparisons demonstrate that the proposed protocol achieves 10.08%–71.34% lower communication overhead than existing schemes across multiple security levels (80-, 112-, and 128-bit) compared to existing protocols.

Total 2