Practical Data Sharing at Untrusted Stores
Xin Pei, Xiaochuan Wu, Liang Sun · 2020 10th Annual Computing and Communication Workshop and Conference (CCWC) · 2020
The most effective way to protect data in remote stores is to adopt cryptographic schemes, so that all of the delegated data are ciphertext. In order to share these encrypted data with others, the Proxy Re-Encryption ($PRE$) technique is proposed. It allows a proxy to convert a ciphertext encrypted under one key into an encryption of the same message under another key, while placing as little trust and reveal to the proxy as necessary to allow it to perform its translations.$PRE$turns out to be the most suitable scheme for remote data sharing and becomes popular with the spread of cloud computing. However, in reality, it is difficult for users to manage their secret keys by themselves and not to authorize others by generating the re-encryption keys. In this proposal, we introduce a distributed key management system ($DKMS$) to manage user keys and handle data sharing requests. The$DKMS$is an honest authority that does not provides any encryption or re-encryption services, thus it is of zero-knowledge to the data. Moreover, the$DKMS$will not store the intact secret keys, which will only appear in runtime environment and be destroyed after lifecycle.