CP-ABSE: A Ciphertext-Policy Attribute-Based Searchable Encryption Scheme

被引:73
作者
Yin, Hui [1 ]
Zhang, Jixin [2 ]
Xiong, Yinqiao [1 ,3 ]
Ou, Lu [2 ]
Li, Fangmin [1 ]
Liao, Shaolin [4 ,5 ]
Li, Keqin [6 ]
机构
[1] Changsha Univ, Coll Comp Engn & Appl Math, Changsha 410022, Hunan, Peoples R China
[2] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Hunan, Peoples R China
[3] Natl Univ Def Technol, Coll Comp, Changsha 410073, Hunan, Peoples R China
[4] Argonne Natl Lab, Lemont, IL 60439 USA
[5] IIT, Dept Elect & Comp Engn, Chicago, IL 60616 USA
[6] SUNY Coll New Paltz, Dept Comp Sci, New Paltz, NY 12561 USA
基金
中国国家自然科学基金;
关键词
Access control; attribute-based encryption; search authorization; searchable encryption; KEYWORD SEARCHES; SECURITY;
D O I
10.1109/ACCESS.2018.2889754
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Searchable encryption provides an effective mechanism that achieves secure search over encrypted data. A popular application model of searchable encryption is that a data owner stores encrypted data to a server and the server can effectively perform keyword-based search over encrypted data according to a query trapdoor submitted by a data user, where the owner's data and the user's queries are kept secret in the server. Recently, many searchable encryptions have been proposed to achieve better security and performance, provide secure data updatable feature (dynamics), and search results verifiable capability (verifiability). However, most of the existing works endow the data user an unlimited search capacities and do not consider a data user's search permissions. In practical application, granting search privileges for data users is a very important measure to enforce data access control. In this paper, we propose an attribute-based searchable encryption scheme by leveraging the ciphertext-policy attribute-based encryption technique. Our scheme allows the data owner to conduct a fine-grained search authorization for a data user. The main idea is that a data owner encrypts an index keyword under a specified access policy, if and only if, a data user's attributes satisfy the access policy, the data user can perform search over the encrypted index keyword. We provide the detailed correctness analyses, performance analyses, and security proofs for our scheme. The extensive experiments demonstrate that our proposed scheme outperforms the similar work CP-ABKS proposed by Zheng on many aspects.
引用
收藏
页码:5682 / 5694
页数:13
相关论文
共 52 条
[1]  
[Anonymous], PLOS ONE
[2]  
[Anonymous], 2003, SECURE INDEXES
[3]  
[Anonymous], 2012, P ACM SIGSAC C COMP
[4]  
Ballard L, 2005, LECT NOTES COMPUT SC, V3783, P414
[5]   Ciphertext-policy attribute-based encryption [J].
Bethencourt, John ;
Sahai, Amit ;
Waters, Brent .
2007 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2007, :321-+
[6]  
Boneh D, 2004, LECT NOTES COMPUT SC, V3027, P506
[7]  
Boneh D, 2007, LECT NOTES COMPUT SC, V4392, P535
[8]   Forward and Backward Private Searchable Encryption from Constrained Cryptographic Primitives [J].
Bost, Raphael ;
Minaud, Brice ;
Ohrimenko, Olga .
CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, :1465-1482
[9]  
Camenisch J, 2009, LECT NOTES COMPUT SC, V5443, P196
[10]   Privacy-Preserving Multi-Keyword Ranked Search over Encrypted Cloud Data [J].
Cao, Ning ;
Wang, Cong ;
Li, Ming ;
Ren, Kui ;
Lou, Wenjing .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (01) :222-233