Authors:
Mukti Padhya
1
and
Devesh C. Jinwala
2
Affiliations:
1
Department of Computer Engineering, Sardar Vallabhbhai National Institute of Technology (SVNIT), Surat and India
;
2
Department of Computer Science and Engineering, Indian Institute of Technology, Jammu and India
Keyword(s):
Searchable Encryption, Data Sharing, Data Retrieval, Cloud Server, Multi-keyword Search, Multi-delegation, Revocation, Break-The-Glass Access.
Related
Ontology
Subjects/Areas/Topics:
Information and Systems Security
;
Security and Privacy in the Cloud
Abstract:
Delegation is the technique of sharing the available rights from the delegator to the delegatee for the purpose data sharing. The Key Aggregate Searchable Encryption (KASE) scheme supports delegation of search rights for any set of ciphertexts using a key of constant-size. However, three critical issues still need to be considered. Firstly, the existing KASE schemes only discuss delegation of rights from the data owner to other user. However, if a subject receiving a delegation cannot perform time-critical task on the shared data, it becomes necessary for the delegatee to further delegate their received rights to another user. Secondly, the existing delegation mechanisms tend to rely on manual processes initiated by end-users. If no authorized user exists to perform (or to delegate) a time-critical task, in such exceptional case, we require mechanism that flexibly handles emergency situations by breaking or by controlled overriding of the standard access permissions. Thirdly, the acc
ess of user in the system changes dynamically and it requires KASE to support user revocation securely while not affecting the legitimate users’ access to the shared files. To address all of the above issues, we propose Revocable KASE with Break-The-Glass access control (BTG-RKASE) to provide (i)fine-grained multi-delegation of available rights from the delegatee to another user,(ii)break-the-glass access mechanism when no authorized user exists to perform (or to delegate) a time-critical task,(iii)revocation of delegated rights (even in case of multi-delegation). The security and empirical analysis shows that BTG-RKASE performs better than the existing KASE schemes.
(More)