(R)CCA Secure Updatable Encryption with Integrity Protection
(R)CCA Secure Updatable Encryption with Integrity Protection
复制标题
(R)CCA 具有完整性保护的安全可更新加密
DOI:
10.1007/978-3-030-17653-2_3
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
A. Rupp
中科院分区:
文献类型:
--
作者:
M. Klooß;A. Lehmann;A. Rupp
An updatable encryption scheme allows a data host to update ciphertexts of a client from an old to a new key, given so-called update tokens from the client. Rotation of the encryption key is a common requirement in practice in order to mitigate the impact of key compromises over time. There are two incarnations of updatable encryption: One is ciphertext-dependent, i.e. the data owner has to (partially) download all of his data and derive a dedicated token per ciphertext. Everspaugh et al. (CRYPTO’17) proposed CCA and CTXT secure schemes in this setting. The other, more convenient variant is ciphertext-independent, i.e., it allows a single token to updateallciphertexts. However, so far, the broader functionality of tokens in this setting comes at the price of considerably weaker security: the existing schemes by Boneh et al. (CRYPTO’13) and Lehmann and Tackmann (EUROCRYPT’18) only achieve CPA security and provide no integrity protection. Arguably, when targeting the scenario of outsourcing data to an untrusted host, plaintext integrity should be a minimal security requirement. Otherwise, the data host may alter or inject ciphertexts arbitrarily. Indeed, the schemes from BLMR13 and LT18 suffer from this weakness, and even EPRS17 only provides integrity against adversaries which cannot arbitrarily inject ciphertexts. In this work, we provide the first ciphertext-independentupdatable encryption schemes with security beyond CPA, in particular providing strong integrity protection. Our constructions and security proofs of updatable encryption schemes are surprisingly modular. We give a generic transformation that allows key-rotation and confidentiality/integrity of the scheme to be treated almost separately, i.e., security of the updatable scheme is derived from simple properties of its static building blocks. An interesting side effect of our generic approach is that it immediately implies the unlinkability of ciphertext updates that was introduced as an essential additional property of updatable encryption by EPRS17 and LT18.
登录
查看更多内容
影响因子:
3
作者:
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
通讯作者:
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
DOI:
10.1145/3133956.3134068
发表时间:
2017
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
G. Herold;M. Hoffmann;M. Klooß;C. Rafols;A. Rupp
通讯作者:
A. Rupp
影响因子:
1.6
作者:
Hofheinz, Dennis;Jager, Tibor
通讯作者:
Jager, Tibor
DOI:
--
发表时间:
2018
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
作者:
Anja Lehmann;Björn Tackmann
通讯作者:
Björn Tackmann
DOI:
10.1007/978-3-319-63688-7_5
发表时间:
2017
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
作者:
Zahra Jafargholi;Chethan Kamath;Karen Klein;Ilan Komargodski;Krzysztof Pietrzak;Daniel Wichs
通讯作者:
Daniel Wichs