arrow
Return

Dynamic Authorization for Private-Keyless Data Custody Services Using Credential-Driven Cryptosystem

delete2026-05-12
delete0
PRE
AI
H
Hai Lu
朱岩 (Yan Zhu)
G
Guizhen Zhu
K
Kewei Lv
DOI:10.1109/tdsc.2026.3692440delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Private-keyless access, serving as an implementation mechanism within policy-based data custody, enables control and authorization based on predefined policies without requiring users to possess a private key. The unforgeability of both user identity and authorization decisions is ensured by the cryptosystem in private-keyless data custody. Hereby, we introduce a novel Cryptographic Resource Enabled Framework (CREF) to simplify key management, enhance security, and increase flexibility of access authorization. Firstly, in the data custody phase, data resource and its session key are uploaded in ciphertext form to CREF, and the access authorization complies with multiple policies designated by the provider. Secondly, in the dynamic authorization phase, traditional keys or keycards are replaced with adequate one-time attribute credentials issued by multiple authorities. CREF makes dynamically cryptographic policy decision according to the credentials and the cryptographic policy (cryptopolicy). Technically, we design the Credentials-Driven Cryptosystem (CDC) over ideal lattice to build anti-quantum confidence for CREF. In CDC, preimage Gaussian sampler is adopted to sample short vector as real-time attribute credential instead of user’s private key. Small policy matrix is implemented to convert monotone policies into optimized cryptopolicies in order to reduce accumulated error. The security analysis confirms that both credentials and cryptopolicies are existentially unforgeable, ensuring the semantic security of the whole CREF. Experimental results indicate CREF has lower storage and computational costs than existing schemes. Meanwhile, with policies’ continuous improvements as system evolves, CREF only need to select a suitable policy among multiple candidates to make authorization decisions without having to reencrypt data.
Keywords:
Security
dynamic authorization
private-keyless access
policy-based data custody
ideal lattice

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

U
University of Chinese Academy of Sciences
Scholars:
6.2K
Papers: 2.5K
Citations: 24.6W
P
peking university
Scholars:
11.7W
Papers: 8.7W
Citations: 146
U
university of science and technology beijing
Scholars:
1.2W
Papers: 4.2K
Citations: 2
researcher View more organizations