Insecurity of Cheng et al.'s Efficient Revocation in Ciphertext-Policy Attribute-Based Encryption Based Cryptographic Cloud Storage
Changji Wang, Jiayuan Wu, Yuan Yuan, Jing Liu · 2017
Ciphertext-policy attribute-based encryption (CPABE) is a promising solution to the problem of fine-grained access control over encrypted data in the cloud. Several CPABE based cryptographic cloud storage systems have been proposed in recent years. However, access policy revocation is expensive in these systems, because data owner has to retrieve, re-encrypt and re-upload the data when access policy updates. To optimize the access policy revocation procedure, Cheng et al. proposed a revocation scheme for CP-ABE based cryptographic cloud storage. In their scheme, the original data is first divided into a number of slices, and then uploaded to the cloud storage. When a revocation occurs, the data owner needs only to retrieve, re-encrypt and re-upload one slice instead of the entire data. They claimed that their scheme is efficient and computationally secure. In this paper, we first point out Cheng et al.'s scheme only preserves all-or-nothing property for one time, then we show that it is susceptible to a fatal attack from the malicious revoked data user who stores the symmetric key or generates extra valid slices.