4.6 Article

Revocable Attribute-Based Encryption With Data Integrity in Clouds

期刊

出版社

IEEE COMPUTER SOC
DOI: 10.1109/TDSC.2021.3065999

关键词

Encryption; Cloud computing; Cryptography; Data integrity; Servers; Finance; Systems architecture; Attribute-based encryption; data integrity; cloud computing; revocable

资金

  1. National Natural Science Foundation of China [62032025, 62076125, 61702236, 61872181]
  2. National Key R&D Program of China [2020YFB1005902]
  3. Australian Research Council Discovery Project [DP180100665]

向作者/读者索取更多资源

This article explores a new security requirement for revocable attribute-based encryption schemes: integrity. It introduces a formal definition and security model for revocable attribute-based encryption with data integrity protection (RABE-DI) and proposes a concrete scheme that ensures confidentiality and integrity. The implementation result and performance evaluation demonstrate the efficiency and practicality of the proposed scheme.
Cloud computing enables enterprises and individuals to outsource and share their data. This way, cloud computing eliminates the heavy workload of local information infrastructure. Attribute-based encryption has become a promising solution for encrypted data access control in clouds due to the ability to achieve one-to-many encrypted data sharing. Revocation is a critical requirement for encrypted data access control systems. After outsourcing the encrypted attribute-based ciphertext to the cloud, the data owner may want to revoke some recipients that were authorized previously, which means that the outsourced attribute-based ciphertext needs to be updated to a new one that is under the revoked policy. The integrity issue arises when the revocation is executed. When a new ciphertext with the revoked access policy is generated by the cloud server, the data recipient cannot be sure that the newly generated ciphertext guarantees to be decrypted to the same plaintext as the originally encrypted data, since the cloud server is provided by a third party, which is not fully trusted. In this article, we consider a new security requirement for the revocable attribute-based encryption schemes: integrity. We introduce a formal definition and security model for the revocable attribute-based encryption with data integrity protection (RABE-DI). Then, we propose a concrete RABE-DI scheme and prove its confidentiality and integrity under the defined security model. Finally, we present an implementation result and provide performance evaluation which shows that our scheme is efficient and practical.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据