An Efficient and Verifiable Encrypted Data Filtering Framework Over Large-Scale Storage in Cloud Edge

被引:1
作者
Huang, Qinlong [1 ]
Wang, Chao [1 ]
Lu, Boyu [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
基金
中国国家自然科学基金;
关键词
Encryption; Cloud computing; Access control; Filtering; Servers; Data models; Standards; Data filtering; matchmaking encryption; verifiability; attribute-based encryption; cloud edge; BILATERAL ACCESS-CONTROL;
D O I
10.1109/TIFS.2024.3456600
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The rapid growth of edge computing is accelerating data subscriptions between cloud platforms and mobile subscribers, but sensitive information in these data faces security and privacy concerns. Fortunately, matchmaking attribute-based encryption (MABE) as a new type of encrypted data filtering mechanism has been introduced in cloud edge, which not only enforces fine-grained access control over the encrypted data, but also allows subscribers to dynamically filter data of interest from authentic publishers through edge nodes. However, filtering entire ciphertext collection in linear time is not feasible for large-scale data storage, and edge nodes may return mismatched or incomplete results due to corruption or compromise. To this end, we propose VDFilter, an efficient and verifiable encrypted data filtering framework over large-scale storage in cloud edge. VDFilter first introduces a verifiable MABE as the underlying primitive, which achieves efficient data filtering in edge nodes with an inverted collection from the ciphertext collection, and verifies the soundness and completeness of filtered results with an accumulation tree. To accommodate the ciphertext collection from multiple publishers, VDFilter deploys the construction of the accumulation tree on the Intel SGX enclave within the cloud server, and utilizes authenticated data structures to guarantee secure and efficient filtered result verification. Finally, we provide formal security proofs for VDFilter and demonstrate its efficiency with extensive experiments. Compared with existing schemes, VDFilter is much more efficient in data storing and filtering even with verification operations, and its computational and communication overhead on the subscriber is also low.
引用
收藏
页码:8248 / 8262
页数:15
相关论文
共 33 条
[1]   FAME: Fast Attribute-based Message Encryption [J].
Agrawal, Shashank ;
Chase, Melissa .
CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, :665-682
[2]  
[Anonymous], 2024, Pub/Sub Notifications for Cloud Storage
[3]   Match Me if You Can: Matchmaking Encryption and Its Applications [J].
Ateniese, Giuseppe ;
Francati, Danilo ;
Nunez, David ;
Venturi, Daniele .
ADVANCES IN CRYPTOLOGY - CRYPTO 2019, PT II, 2019, 11693 :701-731
[4]   Ciphertext-policy attribute-based encryption [J].
Bethencourt, John ;
Sahai, Amit ;
Waters, Brent .
2007 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2007, :321-+
[5]  
Boneh Dan., 2001, ASIACRYPT 01 P 7 INT, P514, DOI [10.1007/3-540-45682-130, DOI 10.1007/3-540-45682-130]
[6]  
Canetti R, 2014, LECT NOTES COMPUT SC, V8383, P113, DOI 10.1007/978-3-642-54631-0_7
[7]   CL-ME: Efficient Certificateless Matchmaking Encryption for Internet of Things [J].
Chen, Biwen ;
Xiang, Tao ;
Ma, Mimi ;
He, Debiao ;
Liao, Xiaofeng .
IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (19) :15010-15023
[8]   Identity-Based Matchmaking Encryption from Standard Assumptions [J].
Chen, Jie ;
Li, Yu ;
Wen, Jinming ;
Weng, Jian .
ADVANCES IN CRYPTOLOGY-ASIACRYPT 2022, PT III, 2022, 13793 :394-422
[9]   Shorter identity-based encryption via asymmetric pairings [J].
Chen, Jie ;
Lim, Hoon Wei ;
Ling, San ;
Wang, Huaxiong ;
Wee, Hoeteck .
DESIGNS CODES AND CRYPTOGRAPHY, 2014, 73 (03) :911-947
[10]  
Costan V., 2016, Cryptol. ePrint Archive