Practical Revocation and Key Rotation
Practical Revocation and Key Rotation
复制标题
DOI:
10.1007/978-3-319-76953-0_9
复制
发表时间:
2018-04
期刊:
影响因子:
--
通讯作者:
Steven Myers;Adam Shull
中科院分区:
文献类型:
--
作者:
Steven Myers;Adam Shull
We consider the problems of data maintenance on untrusted clouds. Specifically, two important use cases: (i) using public-key encryption to enforcedynamicaccess control, and (ii) efficient key rotation.Enabling access revocation is key to enabling dynamic access control, and proxy re-encryption and related technologies have been advocated as tools that allow for revocation on untrusted clouds. Regrettably, the literature assumes that data is encrypted directly with the primitives. Yet, for efficiency reasons hybrid encryption is used, and such schemes are susceptible to key-scraping attacks.For key rotation, currently deployed schemes have insufficient security properties, or are computationally quite intensive. Proposed systems are either still susceptible to key-scraping attacks, or too inefficient to deploy.We propose a new notion of security that is practical for both problems. We show how to construct hybrid schemes that are both resistant to key-scraping attacks and highly efficient in revocation or key rotation. The number of modifications to the ciphertext scales linearly with the security parameter andlogarithmicallywith the file length.