Token Open Security Model for Updatable Encryption

Yang Song, Haiying Gao · 2022

Updatable encryption (UE) is suitable for key rotation and ciphertext data update in cloud storage environment. For most updatable encryption schemes, when the tokens are all open and the keys of the past epochs are corrupted by the adversary, the adversary can easily obtain the keys of all epochs, and the scheme is no longer safe. However, the existing security models for UE often use firewalls and insulated regions to limit the information obtained by the adversary when proving the security of the scheme, and require the adversary not to corrupt all the update tokens. We believe that this limitation is far from the real attack scenario, and in this paper we present a new security model for UE, token open security model, which allows the adversary to corrupt all update tokens and keys of the past epochs. We prove that a secure UE scheme under this model must have no-directional key updates and uni-directional ciphertext updates. We prove an equivalent condition of this model. We also present a general construction approach for UE schemes to satisfy token open security model.

Read the paper · More papers on PaperTik