Restricting the Number of Times That Data Can Be Accessed in Cloud Storage Using TrustZone
Zhengwei Ren, Xin Li, Shiwei Xu, Yan Tong · 2022 22nd IEEE International Symposium on Cluster, Cloud and Internet Computing (CCGrid) · 2022
Data assured deletion can achieve the deletion of outsourced data without possessing it physically in the cloud environment. However, most of existing schemes are designed and implemented on the traditional platforms, which might be not applicable to the scenarios that data is accessed via resource-constrained mobile terminals due to the bandwidth and computation consumptions. In this paper, we present a counter-based data assured deletion scheme using TrustZone, which can restrict the number of times that data can be accessed by restricting the number of times the encryption key can be used on resource-constrained mobile terminals. For this purpose, we bind the number of reads of a secure file to a virtual monotonic counter to count the number of times the key has been used. Then the currently used number of times is compared with the pre-set number of times to check the use condition is satisfied or not. If the comparison result is false, the key is destroyed securely and a public deletion proof is generated. Additionally, we check the hash-based integrity of the key information to detect and prevent the replay attack. In our design, the key retrieve is one-time, which can save the traffic cost. We only use some basic and common cryptographic operations provided by the operating system, which can save the computation cost. The physical security functionalities provided by TrustZone are taken advantage of, which provides a higher security guarantee for our scheme. The simulation implementation and results show our scheme is feasible and practical for use.