Practical Revocation and Key Rotation

Practical Revocation and Key Rotation
复制标题

DOI:
10.1007/978-3-319-76953-0_9
复制
发表时间:
2018-04
期刊:
--
影响因子:
--
通讯作者:
Steven Myers;Adam Shull
Steven Myers;Adam Shull
中科院分区:
其他
文献类型:
--
作者:
Steven Myers;Adam Shull

文献摘要

被引文献

相似文献

我们考虑在不可信云上的数据维护问题。具体来说,有两个重要的用例:(i)使用公钥加密来实施动态访问控制,以及(ii)有效的密钥轮换。启用访问撤销是启用动态访问控制的关键,代理重新加密和相关技术已被提倡作为允许在不受信任的云上撤销的工具。遗憾的是,文献假设数据直接用原语加密。然而,基于效率的考虑,混合加密方案容易受到密钥抓取攻击,而现有的密钥轮换方案安全性不足,或者计算量较大.建议的系统要么仍然容易受到密钥抓取攻击,或部署效率太低。我们提出了一个新的安全概念,这是实际的两个问题。我们展示了如何构建混合方案,既能抵抗密钥刮取攻击,又能高效地撤销或轮换密钥。密文的修改次数与安全参数成线性关系,与文件长度成线性关系。
We consider the problems of data maintenance on untrusted clouds. Specifically, two important use cases: (i) using public-key encryption to enforcedynamicaccess control, and (ii) efficient key rotation.Enabling access revocation is key to enabling dynamic access control, and proxy re-encryption and related technologies have been advocated as tools that allow for revocation on untrusted clouds. Regrettably, the literature assumes that data is encrypted directly with the primitives. Yet, for efficiency reasons hybrid encryption is used, and such schemes are susceptible to key-scraping attacks.For key rotation, currently deployed schemes have insufficient security properties, or are computationally quite intensive. Proposed systems are either still susceptible to key-scraping attacks, or too inefficient to deploy.We propose a new notion of security that is practical for both problems. We show how to construct hybrid schemes that are both resistant to key-scraping attacks and highly efficient in revocation or key rotation. The number of modifications to the ciphertext scales linearly with the security parameter andlogarithmicallywith the file length.