(R)CCA Secure Updatable Encryption with Integrity Protection

(R)CCA Secure Updatable Encryption with Integrity Protection
复制标题

(R)CCA 具有完整性保护的安全可更新加密

DOI:
10.1007/978-3-030-17653-2_3
复制
发表时间:
2019
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
A. Rupp
A. Rupp
中科院分区:
--
文献类型:
--
作者:
M. Klooß;A. Lehmann;A. Rupp

文献摘要

参考文献

被引文献

相似文献

可更新加密方案允许数据主机将客户端的密文从旧密钥更新为新密钥,给定来自客户端的所谓更新令牌。加密密钥的轮换是实践中的常见要求,以减轻密钥泄露随时间的影响。可更新加密有两种形式:一种是密文依赖的,即数据所有者必须(部分)下载他的所有数据并为每个密文导出专用令牌。Everspaugh等人(美国专利局'17)提出了CCA和CTXT安全方案在这种情况下。另一种更方便的变体是密文无关的,即,它允许单个令牌更新所有密文。然而,到目前为止,这种设置中令牌的更广泛功能是以相当弱的安全性为代价的:Boneh等人的现有方案(2013年)和Lehmann和Tackmann(2018年)仅实现CPA安全性,不提供完整性保护。可以说,当目标是将数据外包给不受信任的主机时,明文完整性应该是最低的安全要求。否则,数据主机可以任意地改变或注入密文。事实上,BLMR 13和LT 18的方案都存在这个弱点,甚至EPRS 17也只能提供完整性来对抗不能任意注入密文的对手。在这项工作中,我们提供了第一个密文无关的可更新的加密方案的安全性超过CPA,特别是提供强大的完整性保护。我们的可更新加密方案的构造和安全性证明是令人惊讶的模块化。我们给出了一个通用的转换,允许密钥旋转和机密性/完整性的计划几乎分开对待,即,可更新方案的安全性是从其静态构建块的简单属性导出的。我们的通用方法的一个有趣的副作用是,它立即意味着密文更新的不可链接性,这是EPRS 17和LT 18作为可更新加密的一个重要附加属性引入的。
An updatable encryption scheme allows a data host to update ciphertexts of a client from an old to a new key, given so-called update tokens from the client. Rotation of the encryption key is a common requirement in practice in order to mitigate the impact of key compromises over time. There are two incarnations of updatable encryption: One is ciphertext-dependent, i.e. the data owner has to (partially) download all of his data and derive a dedicated token per ciphertext. Everspaugh et al. (CRYPTO’17) proposed CCA and CTXT secure schemes in this setting. The other, more convenient variant is ciphertext-independent, i.e., it allows a single token to updateallciphertexts. However, so far, the broader functionality of tokens in this setting comes at the price of considerably weaker security: the existing schemes by Boneh et al. (CRYPTO’13) and Lehmann and Tackmann (EUROCRYPT’18) only achieve CPA security and provide no integrity protection. Arguably, when targeting the scenario of outsourcing data to an untrusted host, plaintext integrity should be a minimal security requirement. Otherwise, the data host may alter or inject ciphertexts arbitrarily. Indeed, the schemes from BLMR13 and LT18 suffer from this weakness, and even EPRS17 only provides integrity against adversaries which cannot arbitrarily inject ciphertexts. In this work, we provide the first ciphertext-independentupdatable encryption schemes with security beyond CPA, in particular providing strong integrity protection. Our constructions and security proofs of updatable encryption schemes are surprisingly modular. We give a generic transformation that allows key-rotation and confidentiality/integrity of the scheme to be treated almost separately, i.e., security of the updatable scheme is derived from simple properties of its static building blocks. An interesting side effect of our generic approach is that it immediately implies the unlinkability of ciphertext updates that was introduced as an essential additional property of updatable encryption by EPRS17 and LT18.
DOI: 10.1007/s00145-014-9196-7
发表时间: 2010-08
影响因子: 3
作者:
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
通讯作者: Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
双线性群结构批量验证新技术及其在 Groth-Sahai 证明中的应用
DOI: 10.1145/3133956.3134068
发表时间: 2017
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
G. Herold;M. Hoffmann;M. Klooß;C. Rafols;A. Rupp
通讯作者: A. Rupp
DOI: 10.1007/s10623-015-0062-x
发表时间: 2016-07-01
影响因子: 1.6
作者:
Hofheinz, Dennis;Jager, Tibor
通讯作者: Jager, Tibor
具有泄露后安全性的可更新加密
DOI: --
发表时间: 2018
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Anja Lehmann;Björn Tackmann
通讯作者: Björn Tackmann
适应,避免过度投入
DOI: 10.1007/978-3-319-63688-7_5
发表时间: 2017
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Zahra Jafargholi;Chethan Kamath;Karen Klein;Ilan Komargodski;Krzysztof Pietrzak;Daniel Wichs
通讯作者: Daniel Wichs