Audit Free Cloud Storage via Deniable attribute based Encryption
Main Article Content
Abstract
Cloud storage services have grow popularly. For the importance reason of privacy, many cloud storage encryption schemas has been proposed to secure the data from those who do not have access. All such schemes assumes that cloud storage providers are secure and cannot be hacked. However in practice, some authorities may compel cloud storage providers to make public user secrets and confidential data. We consider the problem of building a secure cloud storage service on top of a public cloud infrastructure where the service provider is not completely trusted by the customer. In this paper a new cloud storage encryption schema is proposed which allows cloud storage providers to protect user privacy. Since authorities cannot tell the obtained secrets are true or false, the cloud storage providers ensure that the user privacy is still securely provided. The proposed schemes believe cloud storage service providers or trusted third parties handling key management are trusted and cannot be hacked. Some times may intercept the communication between users and cloud storage providers and then compel storage providers to release user secrets by using government power or other means. In this case the encrypted data are assumed to be known and storage providers are requested to release user secrets. The proposed Deniable CP-ABE scheme is to build an Audit free cloud storage service. The deniability feature makes coercion invalid, and the ABE property ensures secure cloud data sharing with a fine grained access controlled mechanism.
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
IJCERT Policy:
The published work presented in this paper is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license. This means that the content of this paper can be shared, copied, and redistributed in any medium or format, as long as the original author is properly attributed. Additionally, any derivative works based on this paper must also be licensed under the same terms. This licensing agreement allows for broad dissemination and use of the work while maintaining the author's rights and recognition.
By submitting this paper to IJCERT, the author(s) agree to these licensing terms and confirm that the work is original and does not infringe on any third-party copyright or intellectual property rights.
References
A. Sahai and B. Waters, “Fuzzy identity-based encryption,” in Eurocrypt, 2005, pp. 457–473.
V. Goyal, O. Pandey, A. Sahai, and B. Waters, “Attribute-based encryption for fine-grained access control of encrypted data,” in ACM Conference on Computer and Communications Security, 2006, pp. 89–98.
J. Bethencourt, A. Sahai, and B. Waters, “Ciphertext-policy attribute-based encryption,” in IEEE Symposium on Security and Privacy, 2007, pp. 321–334.
B. Waters, “Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization,” in Public Key Cryptography, 2011, pp. 53–70.
A. Sahai, H. Seyalioglu, and B. Waters, “Dynamic credentials and ciphertext delegation for attribute-based encryption,” in Crypto, 2012, pp. 199–217.
S. Hohenberger and B. Waters, “Attribute-based encryption with fast decryption,” in Public Key Cryptography, 2013, pp. 162–179.
P. K. Tysowski and M. A. Hasan, “Hybrid attribute- and reencryption-based key management for secure and scalable mobile applications in clouds.” IEEE T. Cloud Computing, pp. 172–186, 2013.
Wired. (2014) Spam suspect uses google docs; fbi happy. [Online]. Available: http://www.wired.com/2010/04/cloud-warrant/
Wikipedia. (2014) Global surveillance disclosures (2013present). [Online]. Available: http://en.wikipedia.org/wiki/Global surveillance disclosures (2013-present)