ABDKS: attribute-based encryption with dynamic keyword search in fog computing
Fei MENG, Leixiao CHENG, Mingqiang WANG
ABDKS: attribute-based encryption with dynamic keyword search in fog computing
Attribute-based encryption with keyword search (ABKS) achieves both fine-grained access control and keyword search. However, in the previous ABKS schemes, the search algorithm requires that each keyword to be identical between the target keyword set and the ciphertext keyword set, otherwise the algorithm does not output any search result, which is not conducive to use. Moreover, the previous ABKS schemes are vulnerable to what we call a peer-decryption attack, that is, the ciphertext may be eavesdropped and decrypted by an adversary who has sufficient authorities but no information about the ciphertext keywords.
In this paper, we provide a new system in fog computing, the ciphertext-policy attribute-based encryption with dynamic keyword search (ABDKS). In ABDKS, the search algorithm requires only one keyword to be identical between the two keyword sets and outputs the corresponding correlation which reflects the number of the same keywords in those two sets. In addition, our ABDKS is resistant to peer-decryption attack, since the decryption requires not only sufficient authority but also at least one keyword of the ciphertext. Beyond that, the ABDKS shifts most computational overheads from resource constrained users to fog nodes. The security analysis shows that the ABDKS can resist Chosen-PlaintextAttack (CPA) and Chosen-Keyword Attack (CKA).
access control / attribute-based encryption / keyword search / fog computing / outsourcing
[1] |
Bonomi F, Milito R A, Zhu J, Addepalli S. Fog computing and its role in the internet of things. In: Proceedings of the 1st Edition of the MCC Workshop on Mobile Cloud Computing. 2012, 13–16
CrossRef
Google scholar
|
[2] |
Ivan S, Wen S. The fog computing paradigm: scenarios and security issues. In: Proceedings of Federated Conference on Computer Science and Information Systems. 2014, 1–8
|
[3] |
Yi S, Li C, Li Q. A survey of fog computing: concepts, applications and issues. In: Proceedings of Workshop on Mobile Big Data. 2015, 37–42
CrossRef
Google scholar
|
[4] |
Stojmenovic I, Wen S, Huang X, Luan H. An overview of fog computing and its security issues. Concurrency and Computation: Practice and Experience, 2016, 28(10): 2991–3005
CrossRef
Google scholar
|
[5] |
Sahai A, Waters B. Fuzzy identity-based encryption. In: Cramer R, eds. Advances in Cryptology — EUROCRYPT 2005, Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, Berlin, Heidelberg, 2005, 457–473
CrossRef
Google scholar
|
[6] |
Zheng Q, Xu S, Ateniese G. VABKS: verifiable attribute-based keyword search over outsourced encrypted data. In: Proceedings of IEEE Conference on Computer Communications. 2014, 522–530
CrossRef
Google scholar
|
[7] |
Sun W, Yu S, Lou W, Hou Y T, Li H. Protecting your right: verifiable attribute-based keyword search with fine-grained owner-enforced search authorization in the cloud. IEEE Transactions on Parallel and Distributed Systems, 2016, 27(4): 1187–1198
CrossRef
Google scholar
|
[8] |
Green M, Hohenberger S, Waters B. Outsourcing the decryption of ABE ciphertexts. In: Proceedings of USENIX Security Symposium. 2011
|
[9] |
Xiao M, Zhou J, Liu X, Jiang M. A hybrid scheme for fine-grained search and access authorization in fog computing environment. Sensors, 2017, 17(6): 1423
CrossRef
Google scholar
|
[10] |
Miao Y, Ma J, Liu X, Weng J, Li H, Li H. Lightweight fine-grained search over encrypted data in fog computing. IEEE Transactions on Services Computing, 2019, 12(5): 772–785
CrossRef
Google scholar
|
[11] |
Li J, Shi Y, Zhang Y. Searchable ciphertext-policy attribute-based encryption with revocation in cloud storage. International Journal of Communication Systems, 2017, 30(1): e2942
CrossRef
Google scholar
|
[12] |
Goyal V, Pandey O, Sahai A, Waters B. Attribute-based encryption for fine-grained access control of encrypted data. In: Proceedings of ACM Conference on Computer and Communications Security. 2006, 89–98
CrossRef
Google scholar
|
[13] |
Bethencourt J, Sahai A, Waters B. Ciphertext-policy attribute-based encryption. In: Proceedings of IEEE Symposium on Security and Privacy. 2007, 321–334
CrossRef
Google scholar
|
[14] |
Cheung L, Newport C C. Provably secure ciphertext policy ABE. In: Proceedings of ACM Conference on Computer and Communications Security. 2007, 456–465
CrossRef
Google scholar
|
[15] |
Horváth M. Attribute-based encryption optimized for cloud computing. In: Margaria-Steffen T, Pokorný J, Quisquater J J, Wattenhofer R, eds. SOFSEM 2015: Theory and Practice of Computer Science. Springer, Berlin, Heidelberg, 2015, 566–577
CrossRef
Google scholar
|
[16] |
Wang S, Zhou J, Liu J K, Yu J, Chen J, Xie W. An efficient file hierarchy attribute-based encryption scheme in cloud computing. IEEE Transactions on Information Forensics and Security, 2016, 11(6): 1265–1277
CrossRef
Google scholar
|
[17] |
Li J, Yu Q, Zhang Y. Hierarchical attribute based encryption with continuous leakage-resilience. Information Sciences, 2019, 484: 113–134
CrossRef
Google scholar
|
[18] |
Cheng L, Meng F, Meng X, Zhang Q. Akc-based revocable ABE schemes from LWE assumption. Security and Communication Networks, 2020
CrossRef
Google scholar
|
[19] |
Li J, Huang X, Li J, Chen X, Xiang Y. Securely outsourcing attributebased encryption with checkability. IEEE Transactions on Parallel and Distributed Systems, 2014, 25(8): 2201–2210
CrossRef
Google scholar
|
[20] |
Zhang R, Ma H, Lu Y. Fine-grained access control system based on fully outsourced attribute-based encryption. Journal of Systems and Software, 2017, 125: 344–353
CrossRef
Google scholar
|
[21] |
Li J, Yao W, Zhang Y, Qian H, Han J. Flexible and fine-grained attributebased data storage in cloud computing. IEEE Transactions on Services Computing, 2017, 10(5): 785–796
CrossRef
Google scholar
|
[22] |
Li J, Wang Y, Zhang Y, Han J. Full verifiability for outsourced decryption in attribute based encryption. IEEE Transactions on Services Computing, 2017, 13(3): 478–487
CrossRef
Google scholar
|
[23] |
Zuo C, Shao J, Wei G, Xie M, Ji M. CCA-secure ABE with outsourced decryption for fog computing. Future Generation Computer Systems, 2018, 78: 730–738
CrossRef
Google scholar
|
[24] |
Zhang P, Chen Z, Liu J K, Liang K, Liu H. An efficient access control scheme with outsourcing capability and attribute update for fog computing. Future Generation Computer Systems, 2018, 78: 753–762
CrossRef
Google scholar
|
[25] |
Song D X, Wagner D A, Perrig A. Practical techniques for searches on encrypted data. In: Proceedings of IEEE Symposium on Security and Privacy. 2000, 44–55
|
[26] |
Boneh D, Crescenzo G D, Ostrovsky R, Persiano G. Public key encryption with keyword search. In: Cachin C, Camenisch J L, eds. Advances in Cryptology — EUROCRYPT 2004. Springer, Berlin, Heidelbery, 2004, 506–522
CrossRef
Google scholar
|
[27] |
Wang H, Dong X, Cao Z, Li D. Secure and efficient attribute-based encryption with keyword search. The Computer Journal, 2018, 61(8): 1133–1142
CrossRef
Google scholar
|
[28] |
Cao N, Wang C, Li M, Ren K, Lou W. Privacy-preserving multi-keyword ranked search over encrypted cloud data. In: Proceedings of IEEE International Conference on Computer Communications. 2011, 829–837
CrossRef
Google scholar
|
[29] |
Lu Y, Li J, Zhang Y. Secure channel free certificate-based searchable encryption withstanding outside and inside keyword guessing attacks. IEEE Transactions on Services Computing, 2019
CrossRef
Google scholar
|
[30] |
Li H, Yang Y, Luan T H, Liang X, Zhou L, Shen X S. Enabling finegrained multi-keyword search supporting classified sub-dictionaries over encrypted cloud data. IEEE Transactions on Dependable and Secure Computing, 2016, 13(3): 312–325
CrossRef
Google scholar
|
[31] |
Miao Y, Ma J, Liu X, Wei F, Liu Z, Wang X A. m2-abks: attribute-based multi-keyword search over encrypted personal health records in multiowner setting. Journal of Medical Systems, 2016, 40(11): 1–12
CrossRef
Google scholar
|
[32] |
Cui H, Deng R H, Liu J K, Li Y. Attribute-based encryption with expressive and authorized keyword search. In: Proceedings of Australasian Conference on Information Security and Privacy. 2017, 106–126
CrossRef
Google scholar
|
[33] |
Li J, Lin X, Zhang Y, Han J. KSF-OABE: outsourced attribute-based encryption with keyword search function for cloud storage. IEEE Transactions on Services Computing, 2017, 10(5): 715–725
CrossRef
Google scholar
|
/
〈 | 〉 |