Attribute-based data sharing with flexible and direct revocation in cloud computing

35Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.

Abstract

Attribute-based encryption (ABE) is a promising cryptographic primitive for implementing fine-grained data sharing in cloud computing. However, before ABE can be widely deployed in practical cloud storage systems, a challenging issue with regard to attributes and user revocation has to be addressed. To our knowledge, most of the existing ABE schemes fail to support flexible and direct revocation owing to the burdensome update of attribute secret keys and all the ciphertexts. Aiming at tackling the challenge above, we formalize the notion of ciphertext-policy ABE supporting flexible and direct revocation (FDR-CP-ABE), and present a concrete construction. The proposed scheme supports direct attribute and user revocation. To achieve this goal, we introduce an auxiliary function to determine the ciphertexts involved in revocation events, and then only update these involved ciphertexts by adopting the technique of broadcast encryption. Furthermore, our construction is proven secure in the standard model. Theoretical analysis and experimental results indicate that FDR-CP-ABE outperforms the previous revocation-related methods.

Cite

CITATION STYLE

APA

Zhang, Y., Chen, X., Li, J., Li, H., & Li, F. (2014). Attribute-based data sharing with flexible and direct revocation in cloud computing. KSII Transactions on Internet and Information Systems, 8(11), 4028–4049. https://doi.org/10.3837/tiis.2014.11.021

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free