Paper published in a journal (Scientific congresses, symposiums and conference proceedings)
On the Insecurity of a Method for Providing Secure and Private Fine-Grained Access to Outsourced Data
Rial, Alfredo
2016In Abstract book of 2016 IEEE 8th International Conference on Cloud Computing Technology and Science (CloudCom)
Peer reviewed
 

Files


Full Text
main.pdf
Author postprint (268.52 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Attribute-Based Encryption; Cryptanalysis; Access Control
Abstract :
[en] The protection of sensitive data stored in the cloud is paramount. Among the techniques proposed to provide protection, attribute-based access control, which frequently uses ciphertext-policy attribute-based encryption (CPABE), has received a lot of attention in the last years. Recently, Jahan et al.~(IEEE 40th Conference on Local Computer Networks, 2015) propose a scheme based on CPABE where users have reading and writing access to the outsourced data. We analyze the scheme by Jahan et al.\ and we show that it has several security vulnerabilities. For instance, the cloud server can get information about encrypted messages by using a stored ciphertext and an update of that ciphertext. As another example, users with writing access are able to decrypt all the messages regardless of their attributes. We discuss the security claims made by Jahan et al.\ and point out the reasons why they do not hold. We also explain that existing schemes can already provide the advantages claimed by Jahan et al.
Disciplines :
Computer science
Author, co-author :
Rial, Alfredo ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
On the Insecurity of a Method for Providing Secure and Private Fine-Grained Access to Outsourced Data
Publication date :
December 2016
Event name :
8th IEEE International Conference on Cloud Computing Technology and Science
Event date :
from 12-12-2016 to 15-12-2016
Audience :
International
Journal title :
Abstract book of 2016 IEEE 8th International Conference on Cloud Computing Technology and Science (CloudCom)
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 06 January 2017

Statistics


Number of views
82 (5 by Unilu)
Number of downloads
139 (3 by Unilu)

WoS citations
 
0

Bibliography


Similar publications



Contact ORBilu