Verifiable Computation on Outsourced Encrypted Data
Verifiable Computation on Outsourced Encrypted Data
复制标题
DOI:
10.1007/978-3-319-11203-9_16
复制
发表时间:
2014-09
期刊:
影响因子:
--
通讯作者:
Junzuo Lai;R. Deng;HweeHwa Pang;J. Weng
中科院分区:
文献类型:
--
作者:
Junzuo Lai;R. Deng;HweeHwa Pang;J. Weng
On one hand, homomorphic encryption allows a cloud server to perform computation on outsourced encrypted data but provides no verifiability that the computation is correct. On the other hand, homomorphic authenticator, such as homomorphic signature with public verifiability and homomorphic MAC with private verifiability, guarantees authenticity of computation over outsourced data but does not provide data confidentiality. Since cloud servers are usually operated by third-party providers which are almost certain to be outside the trust domain of cloud users, neither homomorphic encryption nor homomorphic authenticator suffices for verifiable computation on outsourced encrypted data in the cloud. In this paper, we proposeverifiablehomomorphic encryption (VHE), which enablesverifiablecomputation on outsourced encrypted data.We first introduce a new cryptographic primitive called homomorphic encrypted authenticator (HEA), which may be of independent interest. Informally, HEA can be viewed as a homomorphic authenticator in which the authenticator itself does not leak any information about the message it authenticates. Next, we show that thefullyhomomorphic MAC scheme, proposed by Gennaro and Wichs recently, is afullyHEA withweakunforgeability in the sense that an adversary is not allowed to make verification queries. We then propose alinearlyHEA which can tolerateanynumber of malicious verification queries, i.e., it achieves (strong) unforgeability. Finally, we define VHE formally, and give a generic construction of VHE based on homomorphic encryption and HEA. Instantiating the generic construction, we derive afullyVHE withweakverifiability as well as alinearlyVHE with (strong) verifiability.