Oblivious key management allows clients to securely outsource data to cloud in encrypted form without the burden of managing numerous encryption keys. However, several critical issues remain unresolved. Existing designs expose data in the presence of passive leakage from both the key management service (KmS) and the storage service (StS), or combined leakage of ciphertext and keys. More critically, they lack support for irreversible data erasure, leaving deleted data permanently vulnerable to future compromise. Additionally, these systems place excessive trust in authenticated client devices, putting sensitive data at risk in shared or untrusted environments. To address these challenges, we propose $\textsf {EPCS}$ , an Erasable and Portable Cloud Storage with oblivious key management, which guarantees irreversible data erasure. It also supports key updates and enables portable authorized-device access, with file-level permission control enforced by a private mobile device. By minimizing trust in authorized devices, $\textsf {EPCS}$ mitigates data misuse by illegitimate users who may gain access to them. $\textsf {EPCS}$ also ensures forward privacy for deleted files and post-compromise privacy for wrapping keys. Additionally, it resists passive data exposure of KmS and StS, and maintains data confidentiality even in the presence of combined ciphertext and key leakage. Our prototype evaluation demonstrates that $\textsf {EPCS}$ is cross-platform compatible and achieves practical efficiency, maintaining low overhead for file operations through periodic key rotations.
