CP-ABSE: A Ciphertext-Policy Attribute-Based Searchable Encryption Scheme

被引:73
作者
Yin, Hui [1 ]
Zhang, Jixin [2 ]
Xiong, Yinqiao [1 ,3 ]
Ou, Lu [2 ]
Li, Fangmin [1 ]
Liao, Shaolin [4 ,5 ]
Li, Keqin [6 ]
机构
[1] Changsha Univ, Coll Comp Engn & Appl Math, Changsha 410022, Hunan, Peoples R China
[2] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Hunan, Peoples R China
[3] Natl Univ Def Technol, Coll Comp, Changsha 410073, Hunan, Peoples R China
[4] Argonne Natl Lab, Lemont, IL 60439 USA
[5] IIT, Dept Elect & Comp Engn, Chicago, IL 60616 USA
[6] SUNY Coll New Paltz, Dept Comp Sci, New Paltz, NY 12561 USA
基金
中国国家自然科学基金;
关键词
Access control; attribute-based encryption; search authorization; searchable encryption; KEYWORD SEARCHES; SECURITY;
D O I
10.1109/ACCESS.2018.2889754
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Searchable encryption provides an effective mechanism that achieves secure search over encrypted data. A popular application model of searchable encryption is that a data owner stores encrypted data to a server and the server can effectively perform keyword-based search over encrypted data according to a query trapdoor submitted by a data user, where the owner's data and the user's queries are kept secret in the server. Recently, many searchable encryptions have been proposed to achieve better security and performance, provide secure data updatable feature (dynamics), and search results verifiable capability (verifiability). However, most of the existing works endow the data user an unlimited search capacities and do not consider a data user's search permissions. In practical application, granting search privileges for data users is a very important measure to enforce data access control. In this paper, we propose an attribute-based searchable encryption scheme by leveraging the ciphertext-policy attribute-based encryption technique. Our scheme allows the data owner to conduct a fine-grained search authorization for a data user. The main idea is that a data owner encrypts an index keyword under a specified access policy, if and only if, a data user's attributes satisfy the access policy, the data user can perform search over the encrypted index keyword. We provide the detailed correctness analyses, performance analyses, and security proofs for our scheme. The extensive experiments demonstrate that our proposed scheme outperforms the similar work CP-ABKS proposed by Zheng on many aspects.
引用
收藏
页码:5682 / 5694
页数:13
相关论文
共 52 条
[31]   Attribute-Based Encryption with Non-Monotonic Access Structures [J].
Ostrovsky, Rafail ;
Sahai, Amit ;
Waters, Brent .
CCS'07: PROCEEDINGS OF THE 14TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2007, :195-+
[32]   Dynamic Keyword Search With Hierarchical Attributes in Cloud Computing [J].
Peng, Tao ;
Liu, Qin ;
Hu, Baishuang ;
Liu, Jierong ;
Zhu, Jiawei .
IEEE ACCESS, 2018, 6 :68948-68960
[33]   Security Challenges for the Public Cloud [J].
Ren, Kui ;
Wang, Cong ;
Wang, Qian .
IEEE INTERNET COMPUTING, 2012, 16 (01) :69-73
[34]   Fuzzy identity-based encryption [J].
Sahai, A ;
Waters, B .
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2005,PROCEEDINGS, 2005, 3494 :457-473
[35]  
Song DXD, 2000, P IEEE S SECUR PRIV, P44, DOI 10.1109/SECPRI.2000.848445
[36]  
Stefanov Emil, 2014, 21 ANN NETWORK DISTR, P72, DOI DOI 10.14722/NDSS.2014.23298
[37]  
Sun WH, 2014, IEEE INFOCOM SER, P226, DOI 10.1109/INFOCOM.2014.6847943
[38]   Verifiable Privacy-Preserving Multi-Keyword Text Search in the Cloud Supporting Similarity-Based Ranking [J].
Sun, Wenhai ;
Wang, Bing ;
Cao, Ning ;
Li, Ming ;
Lou, Wenjing ;
Hou, Y. Thomas ;
Li, Hui .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (11) :3025-3035
[39]  
Wang C., 2013, P CYB SAF SEC 5 INT, P377
[40]   Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization [J].
Waters, Brent .
PUBLIC KEY CRYPTOGRAPHY - PKC 2011, 2011, 6571 :53-70