{"title":"阈值密码加固可更新遗忘密钥管理","authors":"Changsong Jiang;Chunxiang Xu;Zhen Liu;Xinfeng Dong;Wenzheng Zhang","doi":"10.1109/TIFS.2025.3565371","DOIUrl":null,"url":null,"abstract":"We propose a threshold password-hardening updatable oblivious key management system dubbed TPH-UOKM for cloud storage. In TPH-UOKM, a group of key servers share a user-specific secret key for a user, and assist the user in producing her/his password-derived private key in a threshold and oblivious way, where the password is hardened to resist offline dictionary guessing attacks. Anyone can outsource data protected with the user’s password-derived public key to the cloud server, and merely the user holding the correct password can recover the password-derived private key for data access. TPH-UOKM can accomplish decryption of N ciphertexts with the complexity <inline-formula> <tex-math>$O(1)$ </tex-math></inline-formula> of communication between a user and the key servers, which outperforms existing schemes. TPH-UOKM supports password update. The cloud server can update all protected data of a user with an update token to be accessible only with the new password, which resists password leakage. We present a two-level proactivization mechanism to periodically update user-specific secret key shares and the key servers to thwart perpetual compromise of them, where the renewal of user-specific secret key shares reduces computation and communication costs compared to existing approaches. Provable security and high efficiency of TPH-UOKM are demonstrated by comprehensive analyses and performance evaluations.","PeriodicalId":13492,"journal":{"name":"IEEE Transactions on Information Forensics and Security","volume":"20 ","pages":"4799-4814"},"PeriodicalIF":6.3000,"publicationDate":"2025-04-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Threshold Password-Hardening Updatable Oblivious Key Management\",\"authors\":\"Changsong Jiang;Chunxiang Xu;Zhen Liu;Xinfeng Dong;Wenzheng Zhang\",\"doi\":\"10.1109/TIFS.2025.3565371\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We propose a threshold password-hardening updatable oblivious key management system dubbed TPH-UOKM for cloud storage. In TPH-UOKM, a group of key servers share a user-specific secret key for a user, and assist the user in producing her/his password-derived private key in a threshold and oblivious way, where the password is hardened to resist offline dictionary guessing attacks. Anyone can outsource data protected with the user’s password-derived public key to the cloud server, and merely the user holding the correct password can recover the password-derived private key for data access. TPH-UOKM can accomplish decryption of N ciphertexts with the complexity <inline-formula> <tex-math>$O(1)$ </tex-math></inline-formula> of communication between a user and the key servers, which outperforms existing schemes. TPH-UOKM supports password update. The cloud server can update all protected data of a user with an update token to be accessible only with the new password, which resists password leakage. We present a two-level proactivization mechanism to periodically update user-specific secret key shares and the key servers to thwart perpetual compromise of them, where the renewal of user-specific secret key shares reduces computation and communication costs compared to existing approaches. Provable security and high efficiency of TPH-UOKM are demonstrated by comprehensive analyses and performance evaluations.\",\"PeriodicalId\":13492,\"journal\":{\"name\":\"IEEE Transactions on Information Forensics and Security\",\"volume\":\"20 \",\"pages\":\"4799-4814\"},\"PeriodicalIF\":6.3000,\"publicationDate\":\"2025-04-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Transactions on Information Forensics and Security\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10980223/\",\"RegionNum\":1,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, THEORY & METHODS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Information Forensics and Security","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10980223/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, THEORY & METHODS","Score":null,"Total":0}
We propose a threshold password-hardening updatable oblivious key management system dubbed TPH-UOKM for cloud storage. In TPH-UOKM, a group of key servers share a user-specific secret key for a user, and assist the user in producing her/his password-derived private key in a threshold and oblivious way, where the password is hardened to resist offline dictionary guessing attacks. Anyone can outsource data protected with the user’s password-derived public key to the cloud server, and merely the user holding the correct password can recover the password-derived private key for data access. TPH-UOKM can accomplish decryption of N ciphertexts with the complexity $O(1)$ of communication between a user and the key servers, which outperforms existing schemes. TPH-UOKM supports password update. The cloud server can update all protected data of a user with an update token to be accessible only with the new password, which resists password leakage. We present a two-level proactivization mechanism to periodically update user-specific secret key shares and the key servers to thwart perpetual compromise of them, where the renewal of user-specific secret key shares reduces computation and communication costs compared to existing approaches. Provable security and high efficiency of TPH-UOKM are demonstrated by comprehensive analyses and performance evaluations.
期刊介绍:
The IEEE Transactions on Information Forensics and Security covers the sciences, technologies, and applications relating to information forensics, information security, biometrics, surveillance and systems applications that incorporate these features