Limited Times of Data Access Based on SGX in Cloud Storage

Zhengwei Ren, Xiaoshuang Chen, Jinshan Tang, Lina Wang, Yan Tong, Shiwei Xu · 2021 IEEE International Conference on Systems, Man, and Cybernetics (SMC) · 2021

It is straightforward to encrypt the outsourced data to protect its confidentiality using symmetric cryptography in cloud storage. How to control and restrict the use of the encryption key in data users’ devices becomes one of the critical issues. In most of existing time-based and policy-based schemes, the key cannot be stored locally in data users’ devices, making the traffic cost linear with the data access times as the key should be retrieved in each data access. In this paper, we propose a times-based scheme with Intel SGX to restrict the times the key can be used in the data user’s device to restrict the times of data access. The basic idea is to compare the current used times with the specified maximal times to determine whether the key can be used or not. To this end, we use a monotonic counter to count the times the key has been used. When the use condition is not satisfied, we destroy the key securely and generate public proof so that (i) the encrypted data cannot be accessed anymore, i.e., the data is deleted assuredly, (ii) the deletion can be verified. In addition, a hash-based integrity check approach is utilized to detect and prevent replay attacks. The experimental results on the implemented prototype show our scheme is feasible in practice.

Read the paper · More papers on PaperTik