Secure Data Sharing in Cloud Computing Using
Revocable-Storage Identity-Based Encryption
Abstract
Cloud computing provides a flexible and convenient way for data sharing,
which brings various benefits for both the society and individuals. But there
exists a natural resistance for users to directly outsource the shared data to the cloud server since the data often contain valuable information.
Thus, it is necessary to place cryptographically enhanced access control on the shared data. Identity-basedencryption is
a promising cryptographical primitive to build a practical data sharing system. However, access control is not
static. That is, when some user’s authorization is expired, there should be a
mechanism that can remove him/her from the system. Consequently, the revoked
user cannot access both the previously and subsequently shared data. To
this end, we propose a notion called revocable-storage identity-based encryption (RS-IBE),
which can provide the forward/backward security of ciphertext by introducing
the functionalities of user revocation and ciphertext update simultaneously.
Furthermore, we present a concrete construction of RS-IBE, and prove its
security in the defined security model. The performance comparisons indicate
that the proposed RS-IBE scheme has advantages in terms of functionality and
efficiency, and thus is feasible for a practical and cost-effectivedata-sharing system. Finally, we provide
implementation results of the proposed scheme to demonstrate its
practicability.
No comments:
Post a Comment