Skip to main navigation Skip to search Skip to main content

Efficient and secure encrypted data sharing using proxy re-encryption

  • Kaitai LIANG

Student thesis: Doctoral Thesis

Abstract

To date, many cloud storage systems are able to provide the convenience and exibility on data storage/access for their clients. Cloud service providers enable a user to upload a data in an encrypted form to a public cloud, and next to gain access to the data anywhere anytime by using various portable electronic devices, e.g., personal laptops and smart phones. However, the encrypted data storage mechanism provided by the cloud service providers, to a large extend, limits the efficiency of data sharing because it requires either the data owner or a fully trusted server to decrypt and further to encrypt the data again in such a way that the data can be shared with others without loss of confidentiality. This mechanism might not be desirable when either the data owner is off-line/unavailable or the server is not fully trusted. Proxy Re-Encryption (PRE) is proposed to tackle the above problem. It enables a data owner (hereafter by a data owner we mean a user who can gain access to the data, e.g., a legitimate data receiver, a data original owner) to delegate the decryption rights of some specified encrypted data stored on a cloud to others without revealing the data to the cloud server (i.e. the proxy). It is a useful cryptographic primitive that provides convenience and effectiveness for data sharing as the data owner (even using resource constraint devices) can offload most of computational and communicational cost to clouds. Since its introduction many variants of PRE have been proposed in the literature. Nevertheless, these variants suffer from different types of limitations including security and expressiveness/efficiency. To solve the limitations, we introduce new notions for PRE, and further develop novel systems adapting to the notions. Traditional PRE systems only enable a data owner to delegate the decryption rights of all his/her encrypted data to a delegatee. This "all-or-nothing" sharing mode does not scale well as some fine-grained data sharing is necessary in practice. For instance, the data owner might not want to share his/her data described with "private" but not those with "public". Accordingly, a more practical notion of PRE, Conditional PRE (CPRE) (hereafter we classify Type-based PRE into the category of CPRE as they share the same functionality), is introduced. It allows a delegator to specify under what condition the decryption rights of an encrypted data can be delegated, for example, only sharing all the encrypted files under a directory called "public". Although CPRE explores the exibility of PRE by supporting conditional delegation, how to build a CPRE system with chosen-ciphertext security in the standard model is a long-standing question in the literature. We provide an affirmative result to tackle the problem. We, for the first time, show that a class of hierarchical identity-based encryption schemes can be transferred to building a CPRE system in the standard model. By instantiating our generic transformation, we show that an efficient and concrete CPRE scheme, which is both chosen-ciphertext secure in the standard model and conditional delegation, can be built. The aforementioned CPRE notion only supports single but not multiple recipients. To delegate the decryption rights to a group of delegatees, Conditional Proxy Broadcast Re- Encryption (CPBRE) comes to help, in which an encryption for a group of users can be transformed for another group of users without loss of conditional delegation. Another interesting variant of PRE is Timed-Release PRE (TR-PRE) that enables a delegator to set when to release the decryption rights to the corresponding delegatee. To allow a data owner not only to conditionally delegate the decryption rights of a broadcast encryption of a data to a set of recipients, but also to control when the recipients can gain access to the data, we introduce a new notion called Timed-Release CPBRE (TR-CPBRE). We also propose a concrete construction for TR-CPBRE which can be proven selective identity adaptive chosen-ciphertext secure, and chosen-time period chosen-ciphertext secure in the random oracle model. When compared with the existing CPBRE and TR-PRE schemes, our scheme achieves better efficiency, but also provides a fine-grained delegation of decryption rights to multiple delegatees. To explore the technology of PRE in the identity-based encryption cryptographic setting, Identity-Based Proxy Re-Encryption (IBPRE) is proposed by PRE researchers. It allows an encryption under an identity to be converted to another encryption under a new identity. Although a few unidirectional single-hop IBPRE systems have been built in the literature, none of them is chosen-ciphertext secure in the standard model. In addition, they can not support conditional delegation property (which allows a delegator to specify a condition for ciphertexts such that a proxy can re-encrypt ciphertexts only if the re-encryption key corresponding to the same condition is given). Accordingly, we propose a new notion, which we call Identity-Based Conditional Proxy Re-Encryption (IBCPRE), and a corresponding concrete scheme that not only achieves the property of IBPRE (i.e. identity-based re-encryption), but also supports conditional delegation. Moreover, we prove our scheme secure against adaptive condition and adaptive identity chosen-ciphertext attacks in the standard model. Since the introduction of Multi-Hop Identity-Based PRE (MH-IBPRE) by Green and Ateniese, all the existing MH-IBPRE schemes built in the standard model suffer from an efficiency limitation that the size of ciphertext and the complexity of decryption grow linearly in the number of re-encryption "hops". Moreover, MH-IBPRE cannot offer any conditional delegation of decryption rights. Therefore, we propose a novel MH-IBPRE system that maintains constant-size ciphertext and constant computational complexity regardless of the number of re-encryption hops, in which our scheme is bidirectional, but also supports conditional delegation. We further prove the scheme secure against selective identity and chosen-ciphertext attacks and collusion resistant in the standard model. As of independent interest, we also show that the conditional delegation for a single condition in our scheme can also be extended to a set of conditions. Following the above variants of PRE, a more general notion is introduced, Attribute- Based PRE (ABPRE). This notion combines the technology of PRE with attribute- based encryption. It enables a proxy to convert an encryption under a description (e.g. an access policy/attribute set) to another encryption under a new description (e.g. a new access policy/attribute set). Like traditional attribute-based encryption, ABPRE comes to two avors: one is Ciphertext-Policy ABPRE (CP-ABPRE), and the other is Key-Policy ABPRE (KP-ABPRE). The existing CP-ABPRE systems, however, leave how to achieve adaptive chosen-ciphertext security as an open problem. We propose a new CP-ABPRE scheme to solve the problem by integrating the dual system encryption technology with selective proof technique. The new scheme is able to support any monotonic access structures. Although our scheme is built in the composite order bilinear group, it is proven adaptively chosen-ciphertext secure in the standard model without jeopardizing the expressiveness of access policy. At last, we introduce a new general notion for PRE, which we call Deterministic Finite Automata Based Functional PRE (DFA-based FPRE). Meanwhile, we propose the first and concrete DFA-based FPRE system which adapts to our notion. In our scheme an encrypted message is associated with an arbitrary length index string, and its corresponding decryption is legitimate/valid if and only if a DFA associated with the secret key accepts the string. Furthermore, the above encryption is allowed to be transformed to another ciphertext associated with a new string by a proxy whom is given a re-encryption key, but cannot gain access to the underlying plaintext. This new primitive can be categorized as a KP-ABPRE system, which is the first of its type in the literature. We also prove it fully chosen-ciphertext secure in the standard model.
Date of Award3 Oct 2014
Original languageEnglish
Awarding Institution
  • City University of Hong Kong
SupervisorShek Duncan WONG (Supervisor)

Keywords

  • Data encryption (Computer science)
  • Database security
  • Database management

Cite this

'