scieee AI-readable full text Open interactive document viewer

Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing

Gabriel Assamah

Abstract

Abstract: Cloud storage faces significant security and access control challenges due to reduced user oversight and the emerging threat of quantum computing to traditional cryptographic methods. Existing revocable Identity-Based Encryption (IBE) schemes are limited by their lack of postquantum security, inefficient revocation mechanisms that require re-encryption of data, and cumbersome key update procedures. We propose a post-quantum secure Ring-LWE IBE scheme with dynamic time-based revocation tailored for cloud environments. Our solution is built on the hardness of the Ring Learning with Errors (RLWE) problem to ensure quantum resistance and introduces a novel time-based revocation framework. In our approach, user access is bound to discrete periods and managed through a hierarchical binary tree structured over identities and time. This design eliminates the need to re-encrypt stored data upon user revocation. Instead, a trusted authority periodically distributes lightweight key updates exclusively to non-revoked users. Thanks to the binary tree structure, non-revoked users can compute updated decryption keys with only O (log Nₘₐₓ) overhead in both computation and communication, where Nₘₐₓ is the maximum number of users or periods. Revoked users, having no access to future updates, lose decryption capabilities. We provide formal security proofs showing the scheme’s resistance against adaptive identity and time-period-based attacks, grounded in the RLWE assumption. Overall, our scheme offers an effective combination of post-quantum security, efficient access control, and simplified key management, making it suitable for secure cloud data sharing in the quantum era.

Full text

Indian Journal of Cryptography and Network Security (IJCNS) ISSN: 2582-9238 (Online), Volume-5 Issue-2, November 2025 1 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com Gabriel Assamah, Alimatu Latiff Y, Benjamin Appiah, Regina Esi T, Emmanuel Derry Abstract: Cloud storage faces significant security and access control challenges due to reduced user oversight and the emerging threat of quantum computing to traditional cryptographic methods. Existing revocable Identity-Based Encryption (IBE) schemes are limited by their lack of postquantum security, inefficient revocation mechanisms that require re-encryption of data, and cumbersome key update procedures. We propose a post-quantum secure Ring-LWE IBE scheme with dynamic time-based revocation tailored for cloud environments. Our solution is built on the hardness of the Ring Learning with Errors (RLWE) problem to ensure quantum resistance and introduces a novel time-based revocation framework. In our approach, user access is bound to discrete periods and managed through a hierarchical binary tree structured over identities and time. This design eliminates the need to re-encrypt stored data upon user revocation. Instead, a trusted authority periodically distributes lightweight key updates exclusively to non-revoked users. Thanks to the binary tree structure, non-revoked users can compute updated decryption keys with only O (log Nₘₐₓ) overhead in both computation and communication, where Nₘₐₓ is the maximum number of users or periods. Revoked users, having no access to future updates, lose decryption capabilities. We provide formal security proofs showing the scheme’s resistance against adaptive identity and time-period-based attacks, grounded in the RLWE assumption. Overall, our scheme offers an effective combination of post-quantum security, efficient access control, and simplified key management, making it suitable for secure cloud data sharing in the quantum era. Keywords: IBE, Post-Quantum Cryptography, Ring-LWE, Time-based Revocation, Secure Cloud Storage. Abbreviations: PPT: Probabilistic Polynomial-Time PKI: Public Key Infrastructure IBE: Identity-Based Encryption RLWE: Ring-Learning with Errors ABE: Attribute-Based Encryption PRE: Proxy Re-Encryption Manuscript received on 09 June 2025 | First Revised Manuscript received on 04 July 2025 | Second Revised Manuscript received on 16 October 2025 | Manuscript Accepted on 15 November 2025 | Manuscript published on 30 November 2025. *Correspondence Author(s) Gabriel Assamah*, Department of Computer Science, University of Cape Coast, Cape Coast, Ghana. Email ID: gassam[email protected]h, ORCID ID: 0000-0003-2411-2587 Alimatu Latiff Yussif, Department of Computer Science, University of Cape Coast, Cape Coast, Ghana. Email ID: [email protected], Benjamin Appiah, Department of Computer Science, Ho Technical University, Ho, Ghana. Email: [email protected] Regina Esi Turkson, Department of Computer Science, University of Cape Coast, Cape Coast, Ghana. Email ID: regina.turks[email protected]du.gh Emmanuel Derry, Department of Computer Science, University of Cape Coast, Cape Coast, Ghana. Email ID: [email protected] © The Authors. Published by Lattice Science Publication (LSP). This is an open access article under the CC-BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/) I. INTRODUCTION The increasing prevalence of cloud computing has transformed data storage and processing, enabling costeffective and scalable solutions for big data analytics [1] However, outsourcing data to third-party cloud providers introduces significant security challenges, particularly concerning data confidentiality and fine-grained access control [2] Cryptographic enforcement of security policies is crucial since users lack direct physical control over their data. It is imperative to maintain the confidentiality of sensitive information and restrict access to authorized users, even while accommodating dynamic changes in access privileges, such as revoking access for departing employees or compromised credentials [3]. Traditional cryptographic solutions often rely on Public Key Infrastructure (PKI) to ensure data confidentiality in the cloud. While effective, PKI-based systems demand certificate management, which can be cumbersome in large, dynamic environments with frequent user changes. IdentityBased Encryption (IBE) offers an elegant alternative by using a user's identity (e.g., email address) directly as their public key [4]. This simplifies key distribution, making IBE particularly attractive for secure data sharing in the cloud by eliminating the need for certificate management [5]. Despite its advantages, standard IBE faces a significant challenge in efficient user revocation [6]. When a user's access is revoked, all data encrypted for that user must become unintelligible to them. In standard IBE, this typically requires the data owner or a trusted party to re-encrypt all relevant ciphertexts with keys corresponding to the nonrevoked users. This computationally expensive reencryption process, along with its substantial communication overhead, renders dynamic access control impractical for large-scale cloud data. Moreover, the security of widely deployed public-key cryptographic algorithms, including those underpinning traditional IBE schemes (which rely on discrete logarithms or factorization), is fundamentally threatened by the advent of quantum computing. Shor's algorithm, for instance, can efficiently break these systems on a large-scale quantum computer [7]. Consequently, there is an urgent need to develop post-quantum secure cryptographic schemes that can withstand future attacks by quantum adversaries. Lattice-based cryptography [8], particularly algorithms based on the Ring-Learning with Errors (RLWE) problem [9], stands out as a promising candidate for post-quantum security due to its strong theoretical foundations and efficiency. The convergence Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing 2 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com of these challenges underscores the necessity for a postquantum secure IBE scheme that facilitates efficient user revocation without requiring costly ciphertext re-encryption, thereby ensuring safe, efficient, and verifiable access control for large datasets in cloud environments. While some research has explored revocable IBE [10], many existing constructions suffer from inefficiencies due to key update overhead or data re-encryption upon revocation [6], or they lack the necessary post-quantum security guarantees. Motivated by these obstacles, we propose a new RingLWE Identity-Based Encryption scheme that incorporates Dynamic Time-Based Revocation. This approach is designed to be post-quantum secure, ensuring data confidentiality and efficient access control for clouddelegated storage. Our key contributions are summarized below: A. We introduce a revocation mechanism that functions over discrete periods, issuing periodic, lightweight key updates exclusively to non-revoked users. By employing a hierarchical binary tree structure over user identities and periods, our scheme ensures that both computational and communication overhead for key updates are only O(log Nₘₐₓ), where Nₘₐₓ represents the system’s maximum capacity. This approach reduces user workload and eliminates the need for interaction with encrypted data stored in the cloud. B. The scheme is grounded in the conjectured hardness of the Ring Learning with Errors (RLWE) problem, providing robustness against adversaries with quantum capabilities. Furthermore, it directly uses user identities for encryption, eliminating the need for a complex PKIbased certificate infrastructure. C. Our solution supports effective access control management in post-quantum cloud infrastructures, enabling a trusted authority to revoke access at specific time intervals without requiring data owners or cloud providers to re-encrypt large datasets. The proposed RLWE Identity-Based Encryption scheme with Dynamic Revocation is comprehensively described in Section III, and experimentation is presented in Section IV. The paper is concluded in Section V. II. RELATED WORK The escalating adoption of cloud computing for big data storage necessitates robust data confidentiality and access control, challenging traditional encryption methods due to the dynamic nature of cloud environments [11]. Advanced cryptographic primitives, such as Attribute-Based Encryption (ABE) [12], Proxy Re-Encryption (PRE) [13], and Identity-Based Encryption (IBE) [8], offer promising solutions. IBE simplifies key management by using user identities as public keys, thereby eliminating the need for complex Public Key Infrastructure (PKI) [14]. Concurrently, the looming threat of quantum computing necessitates the development of post-quantum secure cryptographic schemes [15]. Lattice-based cryptography, particularly constructions based on the Learning with Errors (LWE) and Ring Learning with Errors (RLWE) problems, has emerged as a strong candidate due to its efficiency, quantum resistance, and suitability for cloud applications, thanks to its advantages in key/ciphertext size and homomorphic operations [9]. A significant challenge in conventional IBE systems is the lack of an effective mechanism for dynamic user revocation, as a user's private key can decrypt all ciphertexts regardless of changes in privilege or compromise [16]. Static revocation methods are impractical for large-scale cloud storage due to the prohibitive computational cost of re-encrypting all data [17]. To address this, Revocable IBE (RIBE) schemes have been developed, incorporating timebased or attribute-based access control [18]. However, many existing RIBE constructions are vulnerable to quantum attacks due to their reliance on assumptions like RSA or bilinear pairings [19]. This highlights the critical need for post-quantum secure RIBE schemes that can manage dynamic access control in the quantum era [18]. Recent research has explored lattice-based approaches using LWE or RLWE assumptions [19]. Efficient user revocation in dynamic environments often requires sophisticated key management to minimize the burden on the trusted authority and non-revoked users [20]. While naive revocation usually involves costly ciphertext re-encryption, broadcast encryption [21] faces challenges in achieving efficient identity-based revocation with fine-grained time control in IBE without ciphertext modification. Key-updating tree structures, especially binary trees [22], provide a more efficient paradigm, enabling users to compute updated keys by processing only a logarithmic number of nodes, thereby significantly reducing computational and communication latency compared to linear-time operations or ciphertext reencryption. Integrating revocation mechanisms into lattice-based schemes presents unique technical challenges, requiring careful design to preserve security proofs based on lattice problems. Despite advancements in lattice-based AttributeBased Encryption with revocation [6] and Proxy ReEncryption [23], a significant research gap exists in developing a practical and scalable RLWE-based IBE scheme that natively supports dynamic [20], time-based revocation without ciphertext re-encryption, specifically for secure and flexible big data sharing in cloud environments [23]. The proposed scheme aims to bridge this gap by combining the benefits of RLWE-based IBE with a dynamic revocation mechanism based on a binary key-update tree [24]. While prior works have explored RLWE-based revocation [12], binary tree methods [22], and multiauthority R-LWE, this scheme uniquely offers time-based revocation without ciphertext re-encryption (unlike[8]), logarithmic-scale key updates via an enhanced tree structure (improving upon [17], and post-quantum secure access control optimized for cloud environments. It achieves lower computational overhead than [6] while maintaining constant ciphertext sizes, effectively bridging the gap between theoretical RLWE constructions [23] and practical big data requirements [23]. Indian Journal of Cryptography and Network Security (IJCNS) ISSN: 2582-9238 (Online), Volume-5 Issue-2, November 2025 3 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com Fig. 1: The Flowchart Depicts The RLWE Identity-Based Encryption Scheme with Dynamic Revocation. The diagram illustrates the roles of the PKG (Setup, KeyGen, Revoke), Sender (Encrypt using MPK), Recipient (Update, Decrypt), and Cloud Storage. Encrypted data (CT₍ID,t₎) is stored in the Cloud. Dynamic revocation is handled by the PKG publishing revocation information (RevInfoₜ). Non-revoked recipients use RevInfoₜ and their secret key (sk₍ID,t₎) in the Update process to derive the valid decryption key (sk′₍ID,t₎). Revoked users cannot complete the Update. Decryption uses sk′₍ID,t₎ and CT₍ID,t₎. Core encryption and decryption mathematics are shown, based on RLWE III. SCHEME CONSTRUCTION This section provides a formal explanation of our proposed Ring-LWE Identity-Based Encryption (RIBE) scheme with Dynamic Time-Based Revocation. Our revised design ensures cryptographic correctness by adopting a standard primal RLWE-IBE framework. We delineate the precise execution of each algorithm, the role of the hierarchical binary tree in managing user access, and the underlying cryptographic parameters. This approach guarantees post-quantum security that is both practicable and effective in dynamic cloud data sharing environments. A visual representation of the scheme flow is depicted in Fig. 1. A. System Parameters and Structure Our scheme is built upon the polynomial ring Rₚ = ℤₚ[x] / ⟨xⁿ + 1⟩, leveraging the efficiency and conjectured postquantum security of RLWE-based constructions. All cryptographic operations are expressed in terms of polynomials and matrices over Rₚ, or their corresponding coefficient vector representations over ℤₚ. i. Parameters: The security level (λ) and maximum user capacity (Nₘₐₓ) determine the system parameters: ▪ n: The dimension of the ring R_q, typically a power of 2. ▪ q: A prime modulus defining the field ℤ_q, chosen such that q ≡ is one mod 2n to allow for efficient polynomial multiplication via the Number-Theoretic Transform (NTT). ▪ χ: A discrete Gaussian error distribution over ℤ with a slight standard deviation σ. Errors sampled from χ are crucial for the hardness of the underlying lattice problem. ▪ m: A dimensional parameter, often small (e.g., m = 1 or m = 2), defining the number of rows/columns of matrices and vectors over R_q. For simplicity, we consider the case where matrices are 1 × m and vectors are m × 1. ▪ Nₘₐₓ: The maximum number of users or periods supported, determining the binary tree height H = ⌈log₂ Nₘₐₓ⌉. ▪ Binary Tree Structure and Cryptographic Role: A complete binary tree T of height H with Nₘₐₓ leaves is central to our revocation mechanism. ▪ Node Association: Each node (i, j) in the tree (level i, position j) is associated with a secret short vector vᵢ,ⱼ ∈ R_q^m. These secrets are generated hierarchically. ▪ Secret Derivation: The Private Key Generator (PKG) generates a master secret vector v₀,₀ for the root node. For any non-leaf node (i, j), its secret vᵢ,ⱼ is divided between its left child (i+1, 2j) and right child (i+1, 2j+1). A random short vector v_{i+1, 2j} is selected, and the right child’s secret is computed as: v_{i+1, 2j+1} = v_{i,j} - v_{i+1, 2j}. This ensures the additive property: v_{i,j} = v_{i+1, 2j} + v_{i+1, 2j+1} holds consistently throughout the tree. ▪ Identity Mapping: A public function, MapIDToLeaf, deterministically maps a user identity ID to a leaf node (H, j_ID). The sequence of nodes from the root to this leaf defines the user’s path, denoted Path(ID). ▪ Master Public Key (MPK): The MPK is public and used for encryption. ▪ MPK = (A, u, H₁) ▪ A ∈ R_q^{1 × m}: A matrix generated together with a secret trapdoor. Its elements are statistically close to uniform in R_q. ▪ u ∈ R_q: A uniformly random vector. ▪ H₁: {0,1} → R_q*: A cryptographic hash function, modelled as a random oracle, that maps an identity–time pair to a ring element. ▪ Master Secret Key (MSK): The MSK is securely held by the PKG. ▪ MSK = (T_A, v₀,₀) ▪ T_A: A short basis (trapdoor) for the lattice ℒ_q^⊥(A) = { x ∈ R_q^m | A·x ≡ 0 mod q }. This enables the efficient sampling of short vectors for key generation via the SampleD algorithm. ▪ v₀,₀: The secret short vector associated with the root of the binary tree, used to derive all other node secrets. ▪ System State (STₜ): The PKG maintains a state STₜ = (RLₜ, t_curr), which contains: ▪ The revocation list RLₜ ▪ The current period t_curr B. Scheme Algorithms 1) Setup (1^λ, Nₘₐₓ) Executed by the PKG to initialize the system. 1. Select parameters n, q, m, χ based on the security parameter λ. 2. Generate the public matrix A ∈ R_q^{1 × m} and its secret trapdoor T_A using a trapdoor generation algorithm (e.g., RingGenTrap). 3. Sample a uniformly random vector u ∈ R_q. 4. Define a cryptographic hash function H₁: {0,1} → R_q*. 5. Initialize the binary tree secrets: ▪ Sample a short Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing 4 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com master secret vector v₀, ₀ ∈ R_q^m from χ^m. ▪ Recursively, for each node (i, j) from the root downward, define secrets for its children (i+1, 2j) and (i+1, 2j+1): i. Sample a random short vector v_ {i+1, 2j} ← χ^m ii. Set v_ {i+1, 2j+1} = v_{i,j} − v_ {i+1, 2j} 6. Publish the Master Public Key (MPK): (A, u, H₁), Set the Master Secret Key (MSK): (T_A, v₀, ₀). Initialize the System State ST₀ = (∅, 0) 2) KeyGen (MPK, MSK, ID) Executed by the PKG to issue a long-term key to the user ID. 1. Map ID to its corresponding leaf node (H, j_ID) and determine its path, denoted Path (ID). 2. The user’s long-term secret key, sk_ID, consists of the hidden vectors of all sibling nodes of the nodes on Path (ID). Formally: sk_ID = {v_{i,j′} | ∃ (i, j) ∈ Path (ID), (i, j′) is a sibling of (i, j) } 3. Securely transmit sk_ID to the user. This key enables the user to reconstruct the secret of any ancestor node by summing the secrets of its descendant sub-branches. 3) Revoke (MPK, MSK, ID₍revoke₎, t₍eff₎, ST₍t₍eff₎₎) Executed by the PKG to revoke user ID₍revoke₎ from time t₍eff₎ onward. 1. Add ID₍revoke₎ to the revocation list: RL₍t₍eff₎₎ = RL₍t₍eff₎₋₁₎ ∪ {ID₍revoke₎} 2. To generate the public revocation information RevInfo₍t₍eff₎₎, the PKG identifies a minimal set of nodes, called the cover set S_cover, whose subtrees span all non-revoked users. 3. For each node (i, j) ∈ S_cover, the PKG computes and includes its secret vector v_{i,j} in RevInfo₍t₍eff₎₎. 4. Publish: RevInfo₍t₍eff₎₎ = {((i, j), v_{i,j}) | (i, j) ∈ S_cover} 4) Update (MPK, ID, t, sk₍ID₎, {RevInfoₜ′} for all t′ < t) Executed by a non-revoked user at time t to compute a timespecific decryption key. 1. Revocation: Check The user ID first checks if they are in the global revocation list RLₜ. This list is reconstructed by aggregating all public RevInfoₜ′ values broadcast by the PKG for all past periods t′ < t, as well as the current RevInfoₜ. ▪ If ID ∈ RLₜ, the process aborts, and the user cannot obtain a key for time t. 2. PKG-side Key Update Component Generation and Broadcast. For each non-revoked user ID′ at time t, the PKG performs the following: ▪ Derive Target Vector: Compute y₍ID′, t₎ = u − H₁(ID′‖t) ∈ R_q ▪ Compute Key Component: Using its master trapdoor T_A, compute KUP₍ID′,t₎ = SampleD(A, T_A, y₍ID′,t₎, σ) This KUP₍ID′,t₎ is the time-specific key satisfying the decryption equation. ▪ Broadcast Encryption Preparation: Rather than encrypting each KUP₍ID′,t₎ separately for every user, the PKG: i. Identifies a minimal set of nodes in the binary tree whose subtrees cover all non-revoked users. ii. For each such node (i, j), computes a broadcast ciphertext component: BC₍i,j,t₎, which enables users whose path includes this node and who are not revoked to derive their specific KUP₍ID,t₎. iii. The set {BC₍i,j,t₎} is publicly broadcast. 3. User-side Key Update Component Decryption Upon receiving {BC₍i,j,t₎} and RevInfoₜ, the nonrevoked user ID (with their long-term key sk₍ID₎) proceeds: ▪ Identify Relevant Path Nodes: Identify the nodes on their path Path(ID) from the root to their leaf node (H, j_ID). ▪ Reconstruct Path Secret: Using sk₍ID₎ (which holds sibling secrets) and public RevInfoₜ, reconstruct the secret v₀,₀ or the appropriate partial sum needed for decryption. This is only possible if the user is not revoked. ▪ Decrypt KUP via Tree Traversal: i. Use reconstructed secrets to traverse the tree and decrypt the appropriate BC₍i,j,t₎. ii. The user’s sk₍ID₎ allows recursive combination of path and RevInfo secrets to extract their own KUP₍ID,t₎. iii. This decryption costs O (log Nₘₐₓ) polynomial multiplications. ▪ Final Time-Specific Key: The result is the user’s time-specific decryption key: sk′₍ID,t₎, satisfying: A · sk′₍ID,t₎ = u − H₁(ID‖t) mod q This key enables the decryption of ciphertexts for time t. 5) Encrypt (MPK, ID, t, m) Performed by a sender to encrypt a message m ∈ {0, 1} for the user ID at time t. 1. Compute the identity-time hash: h₍ID,t₎ = H₁ (ID || t) ∈ R_q 2. Sample: ▪ A short vector r ∈ R_q^m ▪ Small error polynomials: i. e₁ ∈ R_q^m ii. e₂ ∈ R_q Indian Journal of Cryptography and Network Security (IJCNS) ISSN: 2582-9238 (Online), Volume-5 Issue-2, November 2025 5 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com iii. e₃ ∈ R_q All are sampled from the error distribution χ. 3. Encode the message: Encode(m) = m · ⎣q / 2⎦ ∈ R_q 4. Compute the ciphertext CT₍ID,t₎ = (c₀, c₁, c₂): ▪ c₀ = Aᵗ · r + e₁ ∈ R_q^m ▪ c₁ = uᵗ · r + e₂ ∈ R_q ▪ c₂ = h₍ID,t₎ᵗ · r + e₃ + Encode(m) ∈ R_q 5. Output the ciphertext CT₍ID,t₎ = (c₀, c₁, c₂) 6) Decrypt (MPK, ID, t, sk′₍ID,t₎, CT₍ID,t₎) Executed by a recipient ID with a valid time-specific key sk′₍ID,t₎. 1. The recipient holds a valid key sk′₍ID,t₎ ∈ R_q^m, which is short and satisfies: A · sk′₍ID,t₎ = u − H₁(ID‖t) mod q 2. Parse the ciphertext CT₍ID,t₎ = (c₀, c₁, c₂). 3. Compute the intermediate value d ∈ R_q: d = c₁ − (sk′₍ID,t₎)ᵗ · c₀ mod q 4. Compute the raw message value d′ ∈ R_q: d′ = c₂ − d mod q 5. Recover the message bit m′ by rounding the constant term of d′ to the nearest multiple of ⎣q/2⎦: ▪ If the value is closer to ⎣q/2⎦, then m′ = 1 ▪ Otherwise, m′ = 0 C. Security Analysis We demonstrate the scheme's security by reducing it to the hardness of the Decisional Ring Learning with Errors (RLWE) problem. Our analysis provides a rigorous treatment of IND-ID-CPA security for unrevoked users and formalizes the effectiveness of the revocation mechanism, including resistance to collusion. Theorem 1: If the Decisional RLWE problem is complex for parameters (n, q, χ), then the proposed RIBE scheme is IND-ID-CPA secure in the random oracle model. Proof: We construct a Probabilistic Polynomial-Time (PPT) algorithm 𝔅 that solves the Decisional RLWE problem by interacting with a PPT adversary 𝔄 attacking the IND-IDCPA security of our scheme. 𝔅 receives an RLWE challenge instance (A, y*), where A ∈ Rₚ^ {1 × m} is uniformly random and y* ∈ Rₚ is either an accurate RLWE sample (i.e., y* = Aᵗ * s + e for short s, e) or a uniformly random vector in Rₚ. 𝔅’s goal is to distinguish which case it is. The IND-ID-CPA game is simulated via a sequence of hybrid experiments. Let Adv_𝔄 denote 𝔄’s advantage in determining the challenge ciphertext. We show that if Adv_𝔄 is non-negligible, then 𝔅 can distinguish the RLWE challenge, contradicting the RLWE assumption. Game G₀ (Game): This is the real IND-ID-CPA game. 1. Setup: The Challenger 𝒞 (simulated by 𝔅) runs the Setup algorithm to generate (MPK, MSK). MPK is given to 𝔄. 𝒞 chooses a random challenge identity-time pair (ID₍cₕₐₗ₎, t₍cₕₐₗ₎). 2. Phase 1 (Key Queries): 𝔄 makes adaptive queries for secret keys sk₍ID, t₎ and update keys KUP₍ID, t₎ for any (ID, t) ≠ (ID₍cₕₐₗ₎, t₍cₕₐₗ₎). 𝒞 responds truthfully using MSK. 3. Challenge: 𝔄 outputs two messages (m₀, m₁) and a challenge identity-time pair (ID_c, t_c). If (ID_c, t_c) ≠ (ID₍cₕₐₗ₎, t₍cₕₐₗ₎), 𝔄 aborts. Otherwise, 𝒞 flips a random bit b ∈ {0, 1}, encrypts m_b for (ID_c, t_c) to get CT* = (c₀, c₁, c₂), and sends CT* to 𝔄. 4. Phase 2 (Key Queries): 𝔄 continues to make adaptive queries as in Phase 1. 5. Guess: 𝔄 outputs a guess b' ∈ {0, 1}. Game G₁ (Random Oracle Programming for Challenge Identity): This game is identical to G₀ except for how the random oracle H₁ is handled for the challenge identity-time pair. 1. Setup: 𝔅 receives the RLWE challenge (A, y*). 𝔅 sets the public matrix in MPK to A. 𝔅 chooses a random challenge identity-time pair (ID₍chal₎, t₍chal₎). 𝔅 implicitly knows a simulated trapdoor T_A for A through its ability to perfectly simulate the MPK without having MSK. 𝔅 chooses a random short vector s₍sim₎. 𝔅 programs the random oracle H₁ such that: H₁ (ID₍chal₎ || t₍chal₎) = h*, Where h* is a uniformly random value in R_q (chosen by 𝔅). For any other input (ID || t), H₁ returns a random value on its first query. 𝔅 sets the public vector u in MPK as: u = A · s₍sim₎ + h* 2. Phase 1 (Key Queries): For any query (ID, t) ≠ (ID₍chal₎, t₍chal₎): ▪ If H₁ (ID || t) has been queried before, 𝔅 uses the pre-programmed value. ▪ Otherwise, 𝔅 sets: H₁(ID || t) = A · z₍ID,t₎ - u, where z₍ID,t₎ is a randomly chosen short vector in R_q^m. Then 𝔅 computes: ▪ sk₍ID,t₎ = z₍ID,t₎ ▪ KUP₍ID,t₎ (using its knowledge of the tree secrets) and provides them to 𝔄. This is computationally indistinguishable from genuine keys due to the random oracle model and the properties of RLWE. If 𝔄 queries for (ID₍chal₎, t₍chal₎), 𝔅 aborts. This restriction is standard in IND-CPA games. 3. Challenge: 𝔄 outputs (m₀, m₁) and (ID_c, t_c). If (ID_c, t_c) ≠ (ID₍chal₎, t₍chal₎), 𝔅 aborts. Otherwise, 𝔅 flips a random bit b ∈ {0, 1} and constructs the challenge ciphertext CT* = (c₀, c₁, c₂) for (ID₍chal₎, *t₍chal₎**) encrypting m_b as: ▪ c₀ = y* ▪ c₁ = s₍sim₎ᵗ · y* + e₂′ ▪ c₂ = Encode(m_b) + (h* – A · s₍sim₎)ᵗ · y* + e₃′ where e₂′, e₃′ are small errors from χ. 4. Phase 2 (Key Queries): Same as Phase 1. 5. Guess: 𝔄 outputs b′. Indistinguishability of G₀ and G₁: The only difference between G₀ and G₁ is the way the public parameters (A, u) and the H₁ oracle for (ID₍chal₎, t₍chal₎) are set up. In G₀, the value of u is defined as: u = A · s + H₁ (ID₍chal₎ || t₍chal₎), where s is a truly Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing 6 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com random secret. In contrast, in G₁, u is computed as: u = A · s₍sim₎ + h*, where s₍sim₎ is a short vector chosen by 𝔅, and h* is a uniformly random value. Because A is a uniformly random matrix and H₁ (ID₍chal₎ || t₍chal₎) in G₀ is also random, the resulting distribution of u in both games is statistically identical. Furthermore, the responses to all other random oracle queries in both games are selected uniformly at random on their first invocation, maintaining consistency with the random oracle model. This ensures that, from the adversary's perspective, the behaviour of the two games remains computationally indistinguishable. Hence, the advantage 𝔄 gains in distinguishing between G₀ and G₁ is negligible. Formally, we express this indistinguishability as: |Pr[𝔄 wins in G₀] − Pr[𝔄 wins in G₁] | ≤ negl(λ), where negl(λ) denotes a negligible function in the security parameter λ. Game G₂ (Final Game): This game is identical to G₁ except for the nature of y* in the challenge ciphertext. 1. Setup and Query Phases: These are identical to G₁. 2. Challenge: The adversary 𝔄 outputs a message pair (m₀, m₁) and a challenge identity-time pair (ID_c, t_c). If (ID_c, t_c) ≠ (ID₍chal₎, t₍chal₎), then 𝔅 aborts. Otherwise, 𝔅 flips a random bit b ∈ {0, 1} and constructs the challenge ciphertext CT* = (c₀, c₁, c₂) for (ID₍chal₎, *t₍chal₎**) by encrypting m_b using the received y*. 3. Guess: The adversary 𝔄 outputs a guess b′. Distinguishing y*: 𝔅’s strategy to distinguish the RLWE challenge is to simulate G₁ for the adversary 𝔄. If y* = Aᵗ · r + e₍RLWE₎ (i.e., an accurate RLWE sample), then the challenge ciphertext CT* generated in G₁ is a valid encryption of m_b. Specifically, by substituting Aᵗ · r + e₍RLWE₎ for y* and observing the way c₁ and c₂ are computed, it becomes evident that CT* represents a proper encryption under the assumed public key MPK. In this situation, the adversary’s advantage is: Pr[𝔄 wins in G₁]. On the other hand, if y* is uniformly random, then c₀ = y* is itself uniformly random. Consequently, the expressions: ▪ c₁ = s₍sim₎ᵗ · y* + e₂′ ▪ c₂ = Encode(m_b) + (h* − A · s₍sim₎) ᵗ · y* + e₃′ are also statistically random and reveal no meaningful information about the message m_b, due to the randomness of s₍sim₎, h*, and the noise terms e₂′ and e₃′. Therefore, in this case, 𝔄 gains no advantage and can do no better than guessing b uniformly at random. Thus, the probability of a correct guess is ½. Thus, 𝔅’s ability to distinguish between the two cases of y* is precisely 𝔄’s advantage in G₁, that is: Pr[𝔄 wins in G₁] −½. If 𝔄 has a non-negligible advantage ε, then 𝔅 solves the Decisional RLWE problem with non-negligible advantage ε. This contradicts the assumed hardness of the RLWE problem. The restriction that “the adversary never queries the challenge identity-time pair” is enforced by the abort condition, which is standard in IND-CPA games. If 𝔄 does query the challenge key, it trivially wins, and the reduction aborts, meaning that 𝔅 fails to solve the RLWE problem. Such an adversary 𝔄 is not considered a valid IND-ID-CPA adversary. The hybrid argument rigorously demonstrates that, if this restriction is satisfied, the security of the scheme is tightly linked to the hardness of the RLWE problem. Theorem 2 (Revocation Security): If the Decisional RLWE problem is complex for parameters (n, q, χ) and the random oracle is ideal, then revoked users cannot compute or collude to derive a valid decryption key for any period after their revocation time. Proof: Let ID* be a user revoked at time t₍revoke₎. We aim to show that for any t ≥ t₍revoke₎, ID* (or a collusion of revoked users) cannot obtain a valid decryption key sk₍ID*, t₎. A valid decryption key is a short vector sk′₍ID*, t₎ such that: A · sk′₍ID*, t₎ = u − H₁ (ID* || t), where the master public key is MPK = (A, u) and H₁ is the random oracle. Assume for contradiction that a probabilistic polynomialtime (PPT) adversary 𝔄₍rev₎ (representing ID* or a collusion of revoked users) can compute sk₍ID*, t₎ for some t ≥ t₍revoke₎ with non-negligible probability. We now construct a PPT algorithm 𝔅 that uses 𝔄₍rev₎ to solve the Decisional RLWE problem. 𝔅 receives an RLWE challenge (A, y*), as before. 1. Setup: 𝔅 simulates the Setup algorithm for 𝔄₍rev₎. It sets the public matrix in MPK to A. It selects a random short vector s₍sim₎ and defines: u = A · s₍sim₎ + H₁ (ID* || t*), for a randomly chosen target (ID*, t*), where this pair represents the revoked identity and a future time t.𝔅 programs the random oracle H₁ for all other queries using truly random outputs, following the method from Theorem 1. Additionally, 𝔅 generates the master secrets for the binary tree structure, including v₍0,0₎ and all intermediate node secrets. 2. Revocation and Key Queries: 𝔅 simulates KeyGen queries for any identity ≠ ID* using its knowledge of the tree secrets and by programming H₁ appropriately (again, following Theorem 1) to ensure the generated keys are valid, without needing the trapdoor T₍A₎. When 𝔄₍rev₎ requests Revoke (ID\*, t₍revoke₎) (where t₍revoke₎ ≤ t*), 𝔅 adds ID* to the revocation list RL₍t₍revoke₎₎. 𝔅 then computes and publishes the correct revocation information RevInfo₍t′₎ for all t′ ≥ t₍revoke₎, just as the PKG would, using its knowledge of the tree secrets. For any Update query for ID′ at time t′— where ID′ is not revoked or is ID* but t′ < t₍revoke₎—𝔅 provides the correct update key KUP₍ID′, t′₎ and secret key sk₍ID′, t′₎. 3. Adversary’s Goal: 𝔄₍rev₎ aims to produce a valid secret key sk₍ID*, t₎ for ID* at some time t ≥ t₍revoke₎, a time in which ID* is revoked. Importantly, 𝔄₍rev₎ cannot query the PKG for this key, since the PKG will simply refuse to generate it. Instead, 𝔄₍rev₎ attempts to derive such a key by combining its initial long-term secret, earlier update information, and publicly available RevInfo. 4. Reduction Strategy: If 𝔄₍rev₎ successfully outputs a valid sk₍ID*, t₎ (denoted sk₍output₎), then it must hold that: A · sk₍output₎ = u − H₁ (ID* || t). From the setup, recall that: u Indian Journal of Cryptography and Network Security (IJCNS) ISSN: 2582-9238 (Online), Volume-5 Issue-2, November 2025 7 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com = A · s₍sim₎ + H₁ (ID* || t*). If t = t* then: A · sk₍output₎ = A · s₍sim₎ + H₁ (ID* || t*) − H₁ (ID* || t*) = A · s₍sim₎, so: A · (sk₍output₎ − s₍sim₎) = 0. This implies that 𝔅 has found a short, non-zero vector in the kernel of A, which contradicts the hardness of the RLWE problem and can be used to distinguish whether y* is a valid RLWE sample or uniformly random. More generally, define h₍ID*, t₎ = H₁ (ID* || t). Then a valid secret key sk₍output₎ satisfies: A · sk₍output₎ = u − h₍ID*, t₎. If y* is a true RLWE sample Aᵗ · r + e, then 𝔅’s simulation of u and the H₁ values aligns with the actual scheme. In this real-world setting, 𝔄₍rev₎ successfully outputting sk₍output₎ means a short solution was found to the linear equation, possible only if 𝔄₍rev₎ breaks the RLWE problem. On the other hand, if y* is uniformly random, then the values A, u, and H₁ (ID* || t) are unrelated. The likelihood of 𝔄₍rev₎ producing a short sk₍output₎ that satisfies the equation is negligible due to the difficulty of the Search RLWE problem (which is equivalent to Decisional RLWE). 5. Collusion Resistance: The argument extends naturally to the collusion case. The master secret v₍0,0₎ and all intermediate node secrets v₍i,j₎ are essential to generating update key components. Although RevInfo reveals certain secrets for specific branches, it only discloses those needed for non-revoked users whose access paths traverse those branches. Crucially, RevInfo never reveals the trapdoor T₍A₎, nor does it provide any mechanism for a revoked user to compute the value: A · sk′₍ID, t₎ = u − H₁ (ID || t), without PKG involvement. Even if multiple revoked users combine their long-term secrets (sk₍ID₎ values) and all public RevInfo, they are still unable to derive a valid update key. Doing so would require breaking the RLWE assumption, which is infeasible without trapdoor knowledge held exclusively by the PKG. Thus, collusion among revoked users offers no greater advantage than that of an individual revoked user, and this advantage remains negligible. IV. EXPERIMENTATION The experimental evaluation is conducted on a machine with the following configuration: an NVIDIA GeForce RTX 4070 Super with 16 GB of GPU memory, an Intel Core i9 processor clocked at 3.2 GHz, and 32 GB of system memory. The implementation of the scheme is primarily done in Python. The data used for encryption and decryption during the experiments is the Enron Email Dataset, providing a realistic collection of varying file sizes and structures typical of real-world data that might be stored and shared in a cloud environment. These parameters define the ring dimension (n), the modulus (q), the number of polynomial columns in matrix A and vector u (m), and the standard deviation of the Gaussian error distribution (r). The parameter sets used for evaluation correspond to different security levels: Level 1:(n = 256, q = 7681, m = 2, r = 6.0), Level 3: (n = 512, q = 12289, m = 3, r = 8.0), Level 5: (n = 1024, q = 18433, m = 4, r = 10.0). These parameter sets are selected based on lattice attack complexities to provide post-quantum security approximately equivalent to NIST Security Level 1 (128 bits) or NIST Security Level 3 (192 bits). Higher levels with larger n correspond to stronger security guarantees. Evaluation: We focus on two primary categories of metrics: execution time and storage overhead. These metrics are measured for each of the scheme's algorithms and analyzed for their scalability. D. Execution Time We evaluated the execution time of the core algorithms by measuring the following metrics, averaged over multiple runs in milliseconds: PKG Setup time (T₍Setup₎); Key Generation time per user (T₍KeyGen₎(N)) scaling with system size N; Revocation time per user (T₍Revoke₎(N, R)) encompassing RevInfoₜ generation and scaling with N and revoked users R; User Key Update time (T₍Update₎(N, R)) scaling with N and R; Encryption time (T₍Encrypt₎(|m|)) scaling with message size |m|; and Decryption time (T₍Decrypt₎(|CT|)) scaling with ciphertext size |CT|. The experimental results in Figure 1 reveal that execution time is primarily influenced by the security level, which corresponds to the lattice dimension n. As shown in Figure 2(a) and 1(c), Setup and Decrypt—both reliant on lattice operations—exhibit significant time increases with higher n: Setup grows from 729.7 ms to 8612.7 ms (synthetic) and 844.0 ms to 1772.7 ms (Enron), while Decrypt increases from 548.7 ms to 792.6 ms (artificial) and 348.1 ms to 1772.7 ms (Enron) from Level 1 (n = 256) to Level 5 (n = 1024). This rise stems from the higher complexity of polynomial operations in larger rings R_q, which are central to the security of RLWE-based systems. Key Generation, involving Gaussian sampling, also scales with n, ranging from 24.4 ms to 93.4 ms (synthetic) and 30.9 ms to 89.2 ms (Enron). Revocation time grows moderately, from 56.5 ms to 413.6 ms (artificial) and 67.0 ms to 483.5 ms (Enron). Figures 1(b) and 1(d), focused on Level 5 (n = 1024), show that execution times for KeyGen, Revoke, Encrypt, and Decrypt remain nearly constant as the number of users and emails increases from 10 to 100, thanks to efficient peroperation design and bounded parameters (N₍max₎, |m|, |CT|). The stability across synthetic and real (Enron) datasets confirms that cryptographic workload, rather than data content, dominates performance, supporting the scheme’s scalability and practicality in dynamic, large-user environments. Ring-LWE Identity-Based Encryption with Dynamic Revocation for Cloud Data Sharing 8 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com Figure 2: Execution time comparison (in milliseconds). (a) Synthetic and (c) Enron data: Performance across security levels (Level 1: n = 256, Level 3: n = 512, Level 5: n = 1024). (b) Synthetic and (d) Enron data: Performance scaling with number of users/emails processed at Level 5 (n = 1024) E. Storage Overhead The storage overhead analysis, illustrated in Figure 3, evaluates the sizes (in KB) of key scheme components: master public key (S₍MPK₎), master secret key (S₍MSK₎), user secret key (S₍SK₎), ciphertext for a message of size |m|(S₍CT₎(|m|)), and revocation information (S₍RevInfo₎(N, R)). As security levels increase (i.e., larger n), S₍MPK₎ shows a steep rise from 6.0 KB at Level 1 (n = 256) to 131072 KB at Level 5 (n = 1024), due to the quadratic growth of the public matrix A ∈ R₍q₎^{1 × m} and vector u ∈ R₍q₎^m. S₍MSK₎ also grows, though more gradually, from 16 KB to 18432 KB. The user secret key (S₍SK₎) increases from 4.0 KB to 32 KB. In comparison, the ciphertext size (S₍CT₎) grows modestly from 8.0 KB to 16.0 KB, and revocation information (S₍RevInfo₎) scales from 2.0 KB to 8.0 KB across the same security levels. Figures 2(a) and 2(b) show identical storage results for both synthetic and Enron datasets, confirming that storage overhead depends solely on cryptographic parameters (mainly n) and not on the data content. While the sizes of MPK and MSK become substantial at high security levels, the storage requirements for S₍SK₎, S₍CT₎, and S₍RevInfo₎ remain modest. This affirms the scheme's practicality for cloud storage applications, though the growing size of public parameters warrants caution in resource-constrained environments. F. Scalability Analysis We assess scalability by examining the changes in the execution durations and storage overheads of the algorithms as the system parameters—specifically the number of users (N) and the number of revoked users (R)—are increased. To understand the scheme’s performance characteristics in larger-scale cloud environments, we evaluate the pertinent metrics (e.g., T₍KeyGen₎, T₍Revoke₎, T₍Update₎, S₍RevInfo₎) for varying values of N and R. The experimental results in Figure 3 demonstrate the scheme’s scalability under various operational conditions. Key generation (KeyGen) exhibits linear time growth (200–800 ms) as the number of users increases, while revocation (covering 30% of users) and key updates maintain stable performance within the 400–600 ms range, confirming the practical feasibility of large-scale deployments. The consistent timing patterns observed across operations indicate that the overhead of the revocation mechanism scales sub-linearly with system size. This is supported by the moderate 200 ms difference between base key generation and revocation-inclusive operations. Additionally, the uniform time measurements, which imply a flat response curve across various message sizes, suggest that encryption and decryption costs are primarily determined by fixed lattice operations rather than payload size. Ciphertext storage exhibits minimal variation, a critical advantage for cloud systems that manage diverse data types. Indian Journal of Cryptography and Network Security (IJCNS) ISSN: 2582-9238 (Online), Volume-5 Issue-2, November 2025 9 Published By: Lattice Science Publication (LSP) © Copyright: All rights reserved. Retrieval Number:100.1/ijcns.B144105021125 DOI: 10.54105/ijcns.B1441.05021125 Journal Website: www.ijcns.latticescipub.com Figure 3: Storage overhead comparison across security levels (n=256, 512, 1024) for master/public keys (MPK), secret keys (MSK), user keys (UserKey), ciphertexts (Ciphertext), and revocation data (RevInfo) on 100 users. (a) on Synthetic and (b) Enron Email Dataset. Exact values are recorded across all datasets, demonstrating logarithmic-scale growth in size (KB) G. Time Complexity Comparison Table 1 compares our scheme’s uniform O (n log n) time complexity for Key Generation, Decryption, and Encryption, achieved through NTT-based polynomial multiplication (where n is the ring dimension and m is a constant factor), with various schemes from the literature. While direct comparisons are challenging due to diverse parameters such as m, h, N, d, |S|, |W′|, ℓ, and f [log q], many referenced schemes exhibit complexities that are explicitly dependent on the system size (N) or properties of the revocation set. In contrast, the core operations in our scheme are primarily linked to the cryptographic parameter n. This reflects the efficient performance profile inherent to lattice-based cryptography, making the scheme well-suited for post-quantum cloud environments. Moreover, our approach demonstrates a lower revocation overhead of 𝒪 (log N) and smaller per-user storage (32 KB) compared to the schemes in [6] (as detailed in Table 2). Importantly, our scheme eliminates the need for ciphertext re-encryption, a crucial requirement for scalable and secure cloud storage systems. Unlike [20], our scheme maintains post-quantum security based on the Ring Learning with Errors (RLWE) assumption, aligning with modern cryptographic standards for resistance against quantum adversaries. Figure 4 This figure displays the execution time per operation (in milliseconds) for Key Generation, Key Update, and Revocation (left axis), as well as the size of the Revocation Information (RevInfo size in KB) on the right axis, varying with the number of users. Key Generation exhibits consistent 𝒪 (n log n) scaling, with revocation overhead matching theoretical 𝒪 (log N) expectations for lattice-based constructions. Table-I: Time Complexity Comparison of Cryptographic Schemes. Our Complexity Assumes NTT-Based Multiplication Scheme Encryption Time Complexity Decryption Time Complexity Key Generation Time Complexity [26] 𝒪 ((2mh + 1 + mN) ·f [log q]) 𝒪 (nₖ·m·f [log q]) 𝒪 ((2h − |W′| + N) ·m·f [log q]) [6] 𝒪 ((2mh + 1 + mN) ·f [log q]) 𝒪 (2(2nᵤ + nᵥ − nᵣ) ·m·f [log q]) 𝒪 (2(nₐ + nᵥ − nₖ + 1) (2m + 1) ·f [log q]) [19] 𝒪 ((m·f·|S| + η·f) [log q]) 𝒪 (2nₖ·m·f [log q]) 𝒪 (2|J|·m·f [log q]) [9] O((ℓ + d)·m·n·log q) O ((d + 1) ·m·n·log q) O((ℓ + d)·m²·n·log q) [5] 𝒪S ((2mh + 2n) ·f [log q]) 𝒪 (m·n·f[log q]) 𝒪 ((2h − |W′|) ·m·f [log q]) [9] 𝒪 (n²·log q·log n) 𝒪 (n²·log q·log n) 𝒪 (n²·log q·log n) Ours 𝒪 (n·log n) 𝒪 (n·log n) 𝒪 (n·log n) Table-II: Comparison of Revocation Mechanisms with Empirical Validation Scheme Revocation Type Revocation Cost (per user) Storage Overhead (per user) Ciphertext Reencryption Empirical Validation [6] Time-based (Bilinear) O(N) 48 KB Partial 720 ms @ N=100 [19] Attribute Revocation O(|S|) 64 KB Yes 892 ms @ |S|=50 [13] Latticebased RIBE O(√N) 40 KB No 510 ms @ N=100 Ours Time-based (Binary Tree) O (log N) 32 KB (n=1024) No 413 ms @ N=100 H. Limitations and Future Work Despite the contributions of the RLWE Identity-Based Encryption scheme to post-quantum secure and dynamically revocable cloud data sharing, our Ring-LWE Identity-Based Encryption scheme has inherent limitations that inform future research directions. A primary concern is the reliance on a fully trusted Private Key Generator (PKG) for managing the Master Secret Key (MSK). If the PKG is compromised, it would gravely undermine the entire system's security. Future work should investigate certificateless IBE or threshold cryptographic constructions under the RLWE assumption to mitigate this single point of trust.