An Improvement on "CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage"

被引:2
作者
Cheng, Leixiao [1 ,2 ]
Meng, Fei [3 ,4 ]
机构
[1] Shandong Univ, Sch Math, Jinan 250100, Peoples R China
[2] Shandong Univ, Sch Cyber Sci & Technol, Qingdao 266237, Peoples R China
[3] Beijing Inst Math Sci & Applicat, Beijing 101408, Peoples R China
[4] Tsinghua Univ, Yau Math Ctr, Beijing 100190, Peoples R China
关键词
Access control; Computer bugs; Encryption; Mathematics; Cloud computing; Electronic mail; Public key cryptography; ABE; traceability; authority accountability; auditing; revocation;
D O I
10.1109/TSC.2022.3210114
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Ning et al. proposed the "CryptCloud(+): Secure and Expressive Data Access Control for Cloud Storage" in IEEE Transaction on Services Computing. This work provided two versatile ciphertext-policy attribute-based encryption (CP-ABE) schemes to achieve flexible access control on encrypted data, namely ATER-CP-ABE and ATIR-CP-ABE, both of which have attractive advantages, such as white-box malicious user traceability, semi-honest authority accountability, public auditing and user revocation. However, we find a bug of access control in both schemes, i.e., a non-revoked user with attribute set S can decrypt the ciphertext ct encrypted under any access policy (A, ?), regardless of whether S satisfies (A, ?) or not. This article carefully analyzes the bug, and makes an improvement on Ning's pioneering work, so as to fix it.
引用
收藏
页码:1662 / 1663
页数:2
相关论文
共 2 条
  • [1] Ciphertext-policy attribute-based encryption
    Bethencourt, John
    Sahai, Amit
    Waters, Brent
    [J]. 2007 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2007, : 321 - +
  • [2] CryptCloud+: Secure and Expressive Data Access Control for Cloud Storage
    Ning, Jianting
    Cao, Zhenfu
    Dong, Xiaolei
    Liang, Kaitai
    Wei, Lifei
    Choo, Kim-Kwang Raymond
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (01) : 111 - 124