showSidebars ==
showTitleBreadcrumbs == 1
node.field_disable_title_breadcrumbs.value ==

 

Overview

Public cloud storage has become the backbone of modern enterprise collaboration, prized for its scalability, accessibility, and cost efficiency. Yet a case study of six mainstream cloud storage platforms reveals three persistent security gaps: the lack of native or universally available end-to-end encryption (E2EE), reliance on third-party key-management services that introduce additional trust assumptions and single points of failure, and inflexible or inefficient permission revocation. The most difficult of these is revocation: once a file has been shared, recipients may retain decryption capability indefinitely — and if a revoked user colludes with a malicious cloud insider, conventional cryptographic and provider-enforced controls can be bypassed entirely. 

This technology delivers a secure cloud data-sharing system that solves all three problems simultaneously. Purpose-built for the enterprise environment, it provides genuine end-to-end confidentiality, discretionary (owner-controlled) access control, and real-time, fine-grained permission granting and revocation — without the costly key rotation and redistribution or bulk re-encryption that burden existing approaches. Files remain protected even against a compromised cloud provider that eavesdrops, tampers, or colludes with revoked users.

 

Our Innovation

At the heart of the system is a Trusted Execution Environment (TEE) deployed within the cloud, combined with a newly designed TEE-assisted Verifiable and Conditional Proxy Re-Encryption (VCPRE) scheme. Rather than relying purely on cryptographic revocation — which forces frequent key updates or repeated ciphertext re-encryption — the system uses hardware-enforced isolation to neutralise the collusion attacks that undermine competing designs.

Access sharing is achieved by re-encrypting only the small symmetric data-encryption key (in the file header) from owner to recipient, rather than the entire file, making sharing near-instantaneous regardless of file size. The TEE maintains an internal, per-file share list that updates the moment a user is granted or revoked, enabling real-time, per-file revocation that immediately blocks a revoked user's future access while leaving all unaffected files intact. Because the VCPRE scheme leverages TEE hardware attestation, it eliminates the complex integrity checks and cross-validation between re-encryption keys and ciphertexts required by prior proxy re-encryption methods — achieving Chosen-Ciphertext Attack (CCA) security and re-encryption verifiability at the same time. The complete system's security is formally proven under the rigorous Universal Composability (UC) framework across three subsystems: user, file, and permission management.

 

Technology Features

True End-to-End Encryption: Files are encrypted on the client side using hybrid encryption (AEAD for data, public-key encryption for symmetric keys); plaintext is never exposed to the cloud provider.

No Trusted Third-Party Key Server: The authority (e.g., the enterprise IT department) handles only lightweight one-time system setup and user registration — removing the always-online key-distribution centre that acts as a single point of failure in commercial services.

Real-Time, Fine-Grained Revocation: Per-file share lists inside the TEE allow instant granting and revocation of access. A revoked user is immediately denied future access; access to other files is unaffected.

Collusion Resistance by Hardware Isolation: Hardware-enforced isolation prevents a malicious cloud insider from forwarding partially decrypted content to revoked users — closing a gap left open by purely cryptographic schemes.

Fast Sharing at Any Scale: Only the compact file header (symmetric key) is re-encrypted for sharing. Sharing a 1 GB file takes just 3.27 seconds with a 128-byte re-encryption key.

Robust Threat Coverage: Defends against network eavesdropping, file tampering, impersonation attacks (forged certificates), file-swapping attacks, and cloud–user collusion, under a partially trusted TEE model resilient to side-channel concerns.

Provable, Composable Security: Security formalised and proven under the UC framework, ensuring guarantees hold even when many users and services operate concurrently.

Deployable on Existing Cloud Infrastructure: Prototype validated on a real-world TEE-enabled cloud, integrated with Microsoft OneDrive via standard OAuth 2.0 APIs — demonstrating drop-in compatibility with commercial cloud storage.

 

Potential Applications

Enterprise Content Collaboration & Data Governance: Secure sharing of sensitive corporate documents across departments and external partners, with instant off-boarding and permission changes.

Regulated Industries: Confidential file exchange for finance, legal, healthcare, and government sectors requiring strong E2EE, auditable access control, and provable compliance.

SaaS & Cloud Data Management Platforms: A confidentiality and revocation layer that augments existing OneDrive / Microsoft 365, SharePoint, Google Drive, and multi-cloud environments.

Secure Third-Party and Supply-Chain Sharing: Time-bound, revocable access for contractors, auditors, and vendors, with guaranteed cut-off even against provider-side collusion.

Zero-Trust and Insider-Threat Mitigation: Protection of data-at-rest and data-in-use against compromised cloud insiders, aligning with zero-trust architecture mandates.


Value Proposition & Collaboration Opportunity

This system directly addresses the confidentiality, key-management, and access-governance challenges that enterprise data-management providers face daily. Its proven compatibility with Microsoft 365 / OneDrive makes it a natural enhancement for platforms that manage, migrate, protect, and govern data across the cloud. We welcome the opportunity to explore technology collaboration or licensing to bring hardware-enforced, collusion-resistant secure sharing to enterprise customers.

 

If you're interested in this technology, please contact KTC.