Cryptanalysis of Attribute-Based Data Sharing Scheme for Data Access Security in Cloud Computing

Aoting Hu, Rui Jiang, Songyang Wu · Advances in computer science research · 2015

With the development and the implementation of the data outsourcing technology in cloud computing, there are increasing demands and concerns for the data access security.Recently, Hur proposed a scheme and claimed the following achievements: 1) the key escrow problem.2) realizing finegrained user revocation.However, through our security analysis, there are three security flaws in Hur's scheme.Firstly, the scheme cannot ensure fine-grained user revocation security.We present two attacks, passive attack directed by revoked user and collusion attack, to illustrate its vulnerability, which will lead to disclosing the subsequent encrypted information for a revoked user.Secondly,we find out that the scheme cannot ensureuser secure join as it claimed, which means newly joined user is able to decrypt the message before his joining.Similarly, we present two attacks, passive attack directed by newly joined user and collusion attack, which lead to leakage of previous encrypted data for the new joining user.Thirdly, the key escrow problem cannot be solved completely in the scheme based on Dolev-Yao model, which means there is not any secure channel between the communication entities in, especially between the cloud server and users.Finally, in order to solve the above three security shortages in Hur's scheme, in this paper, we propose three countermeasures, which are efficient to withstand our proposed attacks.

Read the paper · More papers on PaperTik