An Improvement on "CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage"
被引:2
作者:
Cheng, Leixiao
论文数: 0引用数: 0
h-index: 0
机构:
Shandong Univ, Sch Math, Jinan 250100, Peoples R China
Shandong Univ, Sch Cyber Sci & Technol, Qingdao 266237, Peoples R ChinaShandong Univ, Sch Math, Jinan 250100, Peoples R China
Cheng, Leixiao
[1
,2
]
Meng, Fei
论文数: 0引用数: 0
h-index: 0
机构:
Beijing Inst Math Sci & Applicat, Beijing 101408, Peoples R China
Tsinghua Univ, Yau Math Ctr, Beijing 100190, Peoples R ChinaShandong Univ, Sch Math, Jinan 250100, Peoples R China
Meng, Fei
[3
,4
]
机构:
[1] Shandong Univ, Sch Math, Jinan 250100, Peoples R China
[2] Shandong Univ, Sch Cyber Sci & Technol, Qingdao 266237, Peoples R China
[3] Beijing Inst Math Sci & Applicat, Beijing 101408, Peoples R China
[4] Tsinghua Univ, Yau Math Ctr, Beijing 100190, Peoples R China
Recently, Ning et al. proposed the "CryptCloud(+): Secure and Expressive Data Access Control for Cloud Storage" in IEEE Transaction on Services Computing. This work provided two versatile ciphertext-policy attribute-based encryption (CP-ABE) schemes to achieve flexible access control on encrypted data, namely ATER-CP-ABE and ATIR-CP-ABE, both of which have attractive advantages, such as white-box malicious user traceability, semi-honest authority accountability, public auditing and user revocation. However, we find a bug of access control in both schemes, i.e., a non-revoked user with attribute set S can decrypt the ciphertext ct encrypted under any access policy (A, ?), regardless of whether S satisfies (A, ?) or not. This article carefully analyzes the bug, and makes an improvement on Ning's pioneering work, so as to fix it.