• DocumentCode
    3603828
  • Title

    CloudKeyBank: Privacy and Owner Authorization Enforced Key Management Framework

  • Author

    Xiuxia Tian ; Ling Huang ; Wu, Tony ; Xiaoling Wang ; Aoying Zhou

  • Author_Institution
    Coll. of Comput. Sci. & Technol., Shanghai Univ. of Electr. Power, Shanghai, China
  • Volume
    27
  • Issue
    12
  • fYear
    2015
  • Firstpage
    3217
  • Lastpage
    3230
  • Abstract
    Explosive growth in the number of passwords for Web based applications and encryption keys for outsourced data storage well exceeds the management limit of users. Therefore, outsourcing keys (including passwords and data encryption keys) to professional password managers (honest-but-curious service providers) is attracting the attention of many users. However, existing solutions in a traditional data outsourcing scenario are unable to simultaneously meet the following three security requirements for keys outsourcing: (1) Confidentiality and privacy of keys; (2) Search privacy on identity attributes tied to keys; (3) Owner controllable authorization over his/her shared keys. In this paper, we propose CloudKeyBank, the first unified key management framework that addresses all the three goals above. Under our framework, the key owner can perform privacy and controllable authorization enforced encryption with minimum information leakage. To implement CloudKeyBank efficiently, we propose a new cryptographic primitive named Searchable Conditional Proxy Re-Encryption (SC-PRE) which combines the techniques of Hidden Vector Encryption (HVE) and Proxy Re-Encryption (PRE) seamlessly, and propose a concrete SC-PRE scheme based on existing HVE and PRE schemes. Our experimental results and security analysis show the efficiency and security goals are well achieved.
  • Keywords
    authorisation; cloud computing; data privacy; outsourcing; private key cryptography; public key cryptography; CloudKeyBank; HVE; SC-PRE scheme; Web based applications; cryptographic primitive; data encryption keys; hidden vector encryption; honest-but-curious service providers; identity attributes; key confidentiality; key privacy; minimum information leakage; outsourced data storage; owner authorization enforced key management framework; owner controllable authorization; privacy enforced key management framework; professional password managers; search privacy; searchable conditional proxy re-encryption; security analysis; unified key management framework; Authorization; Data privacy; Databases; Encryption; Outsourcing; Privacy; Public key cryptography; Key Management; Keys Outsourcing; SC-PRE; Search Privacy; key management; keys outsourcing; search privacy;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2015.2457903
  • Filename
    7161340