零信任环境下的前向安全多用户可验证动态搜索加密方案

IF 6.2 2区 计算机科学 Q1 COMPUTER SCIENCE, THEORY & METHODS Future Generation Computer Systems-The International Journal of Escience Pub Date : 2025-01-02 DOI:10.1016/j.future.2024.107701
Zhihao Xu , Chengliang Tian , Guoyan Zhang , Weizhong Tian , Lidong Han
{"title":"零信任环境下的前向安全多用户可验证动态搜索加密方案","authors":"Zhihao Xu ,&nbsp;Chengliang Tian ,&nbsp;Guoyan Zhang ,&nbsp;Weizhong Tian ,&nbsp;Lidong Han","doi":"10.1016/j.future.2024.107701","DOIUrl":null,"url":null,"abstract":"<div><div>Privacy-preserving searchable encryption can allow clients to encrypt the data for secure cloud storage, enabling subsequent data retrieval while preserving the privacy of data. In this paper, we initialize the study of constructing a secure dynamic searchable symmetric encryption (DSSE) scheme in a zero-trust environment characterized by the threat model of <em>honest-but-curious data owner (DO)</em> + <em>honest-but-curious data user (DU)</em> + <em>fully malicious cloud server (CS)</em>. To tackle these challenges, we introduce a multi-user DSSE scheme that emphasizes verifiability and privacy while integrating forward security. Our contributions include: Employing the oblivious pseudo-random function (OPRF) protocol for secure <em>DO</em>-<em>DU</em> interactions, ensuring the privacy of <em>DO</em>’s keys and <em>DU</em>’s queried keywords from each other, And maintaining the secure separation of data ownership and usage, Utilizing a multiset hash function-based state chain to achieve forward privacy and support <em>DO</em> updates of encrypted cloud data with verifiable query results Proposing a novel hash-based file encryption and authentication approach to protect file privacy and verify query results. additionally, We provide a comprehensive security analysis and experimental evaluation demonstrating the efficacy and efficiency of our approach. these advancements enhance DSSE schemes under a zero-trust environment, Addressing critical challenges of privacy, Verifiability, And operational efficiency</div></div>","PeriodicalId":55132,"journal":{"name":"Future Generation Computer Systems-The International Journal of Escience","volume":"166 ","pages":"Article 107701"},"PeriodicalIF":6.2000,"publicationDate":"2025-01-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Forward-Secure multi-user and verifiable dynamic searchable encryption scheme within a zero-trust environment\",\"authors\":\"Zhihao Xu ,&nbsp;Chengliang Tian ,&nbsp;Guoyan Zhang ,&nbsp;Weizhong Tian ,&nbsp;Lidong Han\",\"doi\":\"10.1016/j.future.2024.107701\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Privacy-preserving searchable encryption can allow clients to encrypt the data for secure cloud storage, enabling subsequent data retrieval while preserving the privacy of data. In this paper, we initialize the study of constructing a secure dynamic searchable symmetric encryption (DSSE) scheme in a zero-trust environment characterized by the threat model of <em>honest-but-curious data owner (DO)</em> + <em>honest-but-curious data user (DU)</em> + <em>fully malicious cloud server (CS)</em>. To tackle these challenges, we introduce a multi-user DSSE scheme that emphasizes verifiability and privacy while integrating forward security. Our contributions include: Employing the oblivious pseudo-random function (OPRF) protocol for secure <em>DO</em>-<em>DU</em> interactions, ensuring the privacy of <em>DO</em>’s keys and <em>DU</em>’s queried keywords from each other, And maintaining the secure separation of data ownership and usage, Utilizing a multiset hash function-based state chain to achieve forward privacy and support <em>DO</em> updates of encrypted cloud data with verifiable query results Proposing a novel hash-based file encryption and authentication approach to protect file privacy and verify query results. additionally, We provide a comprehensive security analysis and experimental evaluation demonstrating the efficacy and efficiency of our approach. these advancements enhance DSSE schemes under a zero-trust environment, Addressing critical challenges of privacy, Verifiability, And operational efficiency</div></div>\",\"PeriodicalId\":55132,\"journal\":{\"name\":\"Future Generation Computer Systems-The International Journal of Escience\",\"volume\":\"166 \",\"pages\":\"Article 107701\"},\"PeriodicalIF\":6.2000,\"publicationDate\":\"2025-01-02\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Future Generation Computer Systems-The International Journal of Escience\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S0167739X24006654\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, THEORY & METHODS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Future Generation Computer Systems-The International Journal of Escience","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167739X24006654","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, THEORY & METHODS","Score":null,"Total":0}
引用次数: 0

摘要

保护隐私的可搜索加密允许客户端为安全的云存储加密数据,从而在保护数据隐私的同时实现后续数据检索。本文首先研究了在以诚实但好奇的数据所有者(DO) +诚实但好奇的数据用户(DU) +完全恶意云服务器(CS)的威胁模型为特征的零信任环境下构建安全的动态可搜索对称加密(DSSE)方案。为了应对这些挑战,我们引入了一个多用户DSSE方案,该方案强调可验证性和隐私性,同时集成了前向安全性。我们的贡献包括:采用遗忘伪随机函数(OPRF)协议进行DO-DU安全交互,保证了DO密钥和DU查询关键字的私密性,保持了数据所有权和使用的安全分离;利用基于多集哈希函数的状态链实现前向隐私,支持查询结果可验证的加密云数据的DO更新。提出一种新颖的基于哈希的文件加密和认证方法,保护文件隐私,验证查询结果。此外,我们提供了全面的安全性分析和实验评估,证明了我们的方法的有效性和效率。这些进步增强了零信任环境下的DSSE方案,解决了隐私、可验证性和运营效率方面的关键挑战
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Forward-Secure multi-user and verifiable dynamic searchable encryption scheme within a zero-trust environment
Privacy-preserving searchable encryption can allow clients to encrypt the data for secure cloud storage, enabling subsequent data retrieval while preserving the privacy of data. In this paper, we initialize the study of constructing a secure dynamic searchable symmetric encryption (DSSE) scheme in a zero-trust environment characterized by the threat model of honest-but-curious data owner (DO) + honest-but-curious data user (DU) + fully malicious cloud server (CS). To tackle these challenges, we introduce a multi-user DSSE scheme that emphasizes verifiability and privacy while integrating forward security. Our contributions include: Employing the oblivious pseudo-random function (OPRF) protocol for secure DO-DU interactions, ensuring the privacy of DO’s keys and DU’s queried keywords from each other, And maintaining the secure separation of data ownership and usage, Utilizing a multiset hash function-based state chain to achieve forward privacy and support DO updates of encrypted cloud data with verifiable query results Proposing a novel hash-based file encryption and authentication approach to protect file privacy and verify query results. additionally, We provide a comprehensive security analysis and experimental evaluation demonstrating the efficacy and efficiency of our approach. these advancements enhance DSSE schemes under a zero-trust environment, Addressing critical challenges of privacy, Verifiability, And operational efficiency
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
19.90
自引率
2.70%
发文量
376
审稿时长
10.6 months
期刊介绍: Computing infrastructures and systems are constantly evolving, resulting in increasingly complex and collaborative scientific applications. To cope with these advancements, there is a growing need for collaborative tools that can effectively map, control, and execute these applications. Furthermore, with the explosion of Big Data, there is a requirement for innovative methods and infrastructures to collect, analyze, and derive meaningful insights from the vast amount of data generated. This necessitates the integration of computational and storage capabilities, databases, sensors, and human collaboration. Future Generation Computer Systems aims to pioneer advancements in distributed systems, collaborative environments, high-performance computing, and Big Data analytics. It strives to stay at the forefront of developments in grids, clouds, and the Internet of Things (IoT) to effectively address the challenges posed by these wide-area, fully distributed sensing and computing systems.
期刊最新文献
Self-sovereign identity framework with user-friendly private key generation and rule table Accelerating complex graph queries by summary-based hybrid partitioning for discovering vulnerabilities of distribution equipment DNA: Dual-radio Dual-constraint Node Activation scheduling for energy-efficient data dissemination in IoT Blending lossy and lossless data compression methods to support health data streaming in smart cities Energy–time modelling of distributed multi-population genetic algorithms with dynamic workload in HPC clusters
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1