Key-Policy Attribute-Based Encryption With Keyword Search in Virtualized Environments

被引:49
作者
Yu, Yong [1 ,2 ]
Shi, Junbin [1 ]
Li, Huilin [1 ]
Li, Yannan [3 ]
Du, Xiaojiang [4 ]
Guizani, Mohsen [5 ]
机构
[1] Shaanxi Normal Univ, Sch Comp Sci, Xian 710062, Peoples R China
[2] Guangdong Prov Key Lab Data Secur & Privacy Prote, Guangzhou 510632, Peoples R China
[3] Univ Wollongong, Sch Comp & Informat Technol, Wollongong, NSW 2522, Australia
[4] Temple Univ, Dept Comp & Informat Sci, Philadelphia, PA 19122 USA
[5] Qatar Univ, Dept Comp Sci & Engn, Doha, Qatar
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
Encryption; Cloud computing; Access control; Keyword search; Public key; Searchable encryption; fine-grained access control; keyword guessing attack; IDENTITY-BASED ENCRYPTION; FRAMEWORK; SECURITY;
D O I
10.1109/JSAC.2020.2986620
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Cloud computing is a model for convenient, on-demand network access to virtualized environments of configurable computing resources. It is challenging to search data encrypted and stored in cloud storage servers. Searchable encryption enables data users to search on ciphertext without leaking any information about keywords and the plaintext of the data. Currently, a number of searchable encryption schemes have been proposed, but most of them provide unlimited search privileges to data users, which is not desirable in certain scenarios. In this paper, we propose a new construction of searchable encryption with fine-grained access control by using key-policy attribute-based cryptography to generate trapdoors to support AND, OR and threshold gates. The main idea is that the data owner encrypts the index keywords according to the specified access policy. The data user can generate a trapdoor to search on data, if and only if the attributes of the data user satisfy the access policy. We provide formal security proofs for the scheme, including the indistinguishability of ciphertexts and the indistinguishability of trapdoors, which are used to resist the chosen keyword attack and the keyword guessing attack of external adversaries. Comprehensive security analysis and implementation results show that the proposed scheme is provably secure and feasible in real-world applications.
引用
收藏
页码:1242 / 1251
页数:10
相关论文
共 28 条
[1]   Searchable encryption revisited: Consistency properties, relation to anonymous IBE, and extensions [J].
Abdalla, Michel ;
Bellare, Mihir ;
Catalano, Dario ;
Kiltz, Eike ;
Kohno, Tadayoshi ;
Lange, Tanja ;
Malone-Lee, John ;
Neven, Gregory ;
Paillier, Pascal ;
Shi, Haixia .
JOURNAL OF CRYPTOLOGY, 2008, 21 (03) :350-391
[2]  
Boneh D, 2004, LECT NOTES COMPUT SC, V3027, P506
[3]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[4]  
Boneh D, 2007, LECT NOTES COMPUT SC, V4392, P535
[5]  
Camenisch J, 2009, LECT NOTES COMPUT SC, V5443, P196
[6]   Efficient and Expressive Keyword Search Over Encrypted Data in Cloud [J].
Cui, Hui ;
Wan, Zhiguo ;
Deng, Robert H. ;
Wang, Guilin ;
Li, Yingjiu .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (03) :409-422
[7]  
Du X., 2001, 2001 IEEE/IFIP International Symposium on Integrated Network Management Proceedings. Integrated Network Management VII. Integrated Management Strategies for the New Millennium (Cat. No.01EX470), P453, DOI 10.1109/INM.2001.918059
[8]  
Goh E.-J., 2003, Report 2003/216
[9]   Secure conjunctive keyword search over encrypted data [J].
Golle, P ;
Staddon, J ;
Waters, B .
APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PROCEEDINGS, 2004, 3089 :31-45
[10]  
Goyal V., 2006, P 2006 INT C PRIVACY, P1