Threshold Ciphertext Policy Attribute-Based Encryption with Constant
Size Ciphertexts文章中解密公式推导
推导公式
M
=
C
0
⋅
e
(
C
2
,
D
2
)
∖
e
(
C
1
,
D
1
)
M=C0 \cdot e(C2,D2) \setminus e(C1,D1)
M=C0⋅e(C2,D2)∖e(C1,D1)
C
0
=
M
⋅
Z
s
C0=M \cdot Z^{s}
C0=M⋅Zs
C
1
=
g
s
C1=g^{s}
C1=gs
C
2
=
(
h
0
∏
j
∈
S
⋃
Ω
h
j
)
s
C2=(h0 \prod_{j \in S \bigcup \Omega}^{}h_j)^{s}
C2=(h0j∈S⋃Ω∏hj)s
D
1
=
∏
i
∈
A
′
⋃
Ω
(
a
i
∏
i
∈
S
⋃
Ω
,
j
≠
i
(
c
i
,
j
)
)
Δ
i
,
A
′
⋃
Ω
(
0
)
D1=\prod_{i \in {A}'\bigcup \Omega}(a_i \prod_{i \in S\bigcup \Omega,j\neq i}(c_{i,j}))^{\Delta _{i,{A}'\bigcup \Omega}(0)}
D1=i∈A′⋃Ω∏(aii∈S⋃Ω,j=i∏(ci,j))Δi,A′⋃Ω(0)
D
2
=
∏
i
∈
A
′
⋃
Ω
(
b
i
)
Δ
i
,
A
′
⋃
Ω
(
0
)
D2=\prod_{i \in {A}'\bigcup \Omega}(b_i)^{\Delta _{i,{A}'\bigcup\Omega}(0)}
D2=i∈A′⋃Ω∏(bi)Δi,A′⋃Ω(0)
推导
M
=
C
0
⋅
e
(
C
2
,
D
2
)
∖
e
(
C
1
,
D
1
)
M=C0 \cdot e(C2,D2) \setminus e(C1,D1)
M=C0⋅e(C2,D2)∖e(C1,D1)
=
M
⋅
e
(
g
,
g
2
)
s
x
⋅
e
(
C
2
,
D
2
)
e
(
C
1
,
D
1
)
=\frac {M \cdot e(g,g_2)^{sx} \cdot e(C2,D2) }{e(C1,D1)}
=e(C1,D1)M⋅e(g,g2)sx⋅e(C2,D2)
化
简
e
(
C
2
,
D
2
)
e
(
C
1
,
D
1
)
:
化简 \frac{e(C2,D2)}{e(C1,D1)}:
化简e(C1,D1)e(C2,D2):
e
(
(
h
0
h
j
(
j
∈
S
⋃
Ω
)
)
s
,
g
∑
i
∈
A
′
⋃
Ω
r
i
⋅
Δ
i
,
A
′
⋃
Ω
(
0
)
)
e
(
g
s
,
g
2
∑
q
(
i
)
⋅
Δ
i
,
A
′
⋃
Ω
(
0
)
[
(
h
0
h
i
)
r
i
⋅
h
j
(
j
∈
S
⋃
Ω
,
j
≠
i
)
r
i
]
∑
Δ
i
,
A
′
⋃
Ω
(
0
)
)
\frac{e((h0hj_{(j \in S \bigcup \Omega)})^s,g^{\sum_{i\in {A}'\bigcup \Omega}^{}ri \cdot\Delta _{i,{A}'\bigcup \Omega}(0)})}{e(g^s,g_2^{\sum q(i)\cdot \Delta _{i,{A}'\bigcup \Omega}(0)}[(h0hi)^{r_i}\cdot hj_{(j \in S \bigcup \Omega,j\neq i)}^{ri}]^{\sum \Delta_{i,{A}'\bigcup \Omega(0)}})}
e(gs,g2∑q(i)⋅Δi,A′⋃Ω(0)[(h0hi)ri⋅hj(j∈S⋃Ω,j=i)ri]∑Δi,A′⋃Ω(0))e((h0hj(j∈S⋃Ω))s,g∑i∈A′⋃Ωri⋅Δi,A′⋃Ω(0))
=
e
(
(
h
0
h
j
(
j
∈
S
⋃
Ω
)
)
s
,
g
∑
i
∈
A
′
⋃
Ω
r
i
⋅
Δ
i
,
A
′
⋃
Ω
(
0
)
)
e
(
g
s
,
g
2
x
)
⋅
e
(
g
s
,
(
h
0
h
i
h
j
(
j
∈
S
⋃
Ω
,
j
≠
i
)
)
∑
Δ
i
,
A
′
⋃
Ω
(
0
)
)
=\frac{e((h0hj_{(j \in S \bigcup \Omega)})^s,g^{\sum_{i\in {A}'\bigcup \Omega}^{}ri \cdot\Delta _{i,{A}'\bigcup \Omega}(0)})}{e(g^s,g_{2}^x)\cdot e(g^s,(h0hihj_{(j \in S\bigcup \Omega,j \neq i)})^{\sum \Delta _{i,{A}' \bigcup \Omega(0)}} )}
=e(gs,g2x)⋅e(gs,(h0hihj(j∈S⋃Ω,j=i))∑Δi,A′⋃Ω(0))e((h0hj(j∈S⋃Ω))s,g∑i∈A′⋃Ωri⋅Δi,A′⋃Ω(0))
=
1
e
(
g
s
,
g
2
x
)
=
1
e
(
g
,
g
2
)
s
x
=\frac{1}{e(g^s,g_2 ^x)}=\frac{1}{e(g,g_2)^{sx}}
=e(gs,g2x)1=e(g,g2)sx1
总
体
化
简
得
M
.
总体化简得M.
总体化简得M.
(
注
意
(
j
∈
S
⋃
Ω
,
j
≠
i
)
和
(
j
∈
S
⋃
Ω
)
区
别
在
于
h
i
)
(注意(j \in S\bigcup \Omega,j \neq i)和(j \in S\bigcup \Omega)区别在于h_i)
(注意(j∈S⋃Ω,j=i)和(j∈S⋃Ω)区别在于hi)