高级检索

基于属性数据库的前向隐私动态可搜索对称加密可验证方案

Verifiable DSSE with Forward Privacy based on Attribute Database

  • 摘要: 动态可搜索对称加密(dynamic searchable symmetric encryption, DSSE)技术使用户能够基于关键字对云端服务器托管的加密数据库进行数据检索与更新,同时实现隐私保护。前向隐私是当前DSSE方案必须具备的关键安全特性。然而,现有大多数DSSE前向隐私方案并不适用于属性数据库,且其构建基于云服务器“诚实但好奇”的假设,缺乏验证结果的能力。为解决这一问题,本文提出一种专为属性数据库设计的可验证DSSE方案。具体而言,就是将属性元素整合到安全索引的构建中,并引入状态链结构,在确保前向隐私的同时实现细粒度搜索。此外,基于对称密码原语设计了一种新的累积验证标签,确保用户能获取正确且完整的搜索结果。实验评估与安全分析表明,该方案在搜索、更新和验证效率方面均表现出色,且安全性也得到充分验证。

     

    Abstract: Dynamic searchable symmetric encryption (DSSE) enables users to retrieve and update data in encrypted databases hosted on cloud servers based on keywords while ensuring privacy protection. Forward privacy, which is a key security feature that current DSSE schemes must possess. Nevertheless, most existing DSSE forward privacy schemes are not suitable for attribute databases, and their construction is based on the assumption that the cloud server is “honest-but-curious”, which means lacking the ability to verify results. To address this issue, this article propose a verifiable DSSE scheme specifically designed for attribute databases. Specifically, this article integrates attribute elements into the construction of secure indexes and introduce a state chain structure to achieve fine-grained search while ensuring forward privacy. Furthermore, based on symmetric cryptographic primitives, this article designs a new cumulative verification tag to ensure that users can obtain correct and complete search results. Experimental evaluation and security analysis show that this scheme demonstrates excellent performance in search, update, and verification efficiency while its security is fully validated.

     

/

返回文章
返回