Next: Key distribution
Up: Threat model
Previous: Trusted client machine
Plutus allows owners of files to revoke other people's rights to access
those files. Following a revocation, we assume that it is acceptable for
the revoked reader to read unmodified or cached files. A revoked reader,
however, must not be able to read updated files, nor may a revoked writer
be able to modify the files. Settling for lazy revocation
trades re-encryption cost for a degree of security.
We elaborate on lazy revocation in Section 3.4.
2003-01-06