Verifiable Computation on Outsourced Encrypted Data

Verifiable Computation on Outsourced Encrypted Data
复制标题

DOI:
10.1007/978-3-319-11203-9_16
复制
发表时间:
2014-09
期刊:
--
影响因子:
--
通讯作者:
Junzuo Lai;R. Deng;HweeHwa Pang;J. Weng
Junzuo Lai;R. Deng;HweeHwa Pang;J. Weng
中科院分区:
其他
文献类型:
--
作者:
Junzuo Lai;R. Deng;HweeHwa Pang;J. Weng

文献摘要

被引文献

相似文献

一方面,同态加密允许云服务器对外包加密数据进行计算,但无法验证计算是否正确。另一方面,同态认证器,例如具有公开可验证性的同态签名和具有私有可验证性的同态MAC,保证了外包数据计算的真实性,但不提供数据机密性。由于云服务器通常由第三方提供商运营,而这些第三方提供商几乎肯定不在云用户的信任域之外,因此同态加密和同态认证器都不足以对云中外包加密数据进行可验证的计算。在本文中,我们提出了可验证的同态加密(VHE),它可以对外包加密数据进行可验证的计算。我们首先引入一种新的密码原语,称为同态加密验证器(HEA),它可能具有独立的利益。非正式地,HEA 可以被视为同态验证器,其中验证器本身不会泄露有关其验证的消息的任何信息。接下来,我们证明 Gennaro 和 Wichs 最近提出的全同态 MAC 方案是一个完全 HEA,具有弱不可伪造性,即不允许对手进行验证查询。然后,我们提出了 alinearlyHEA,它可以容忍任意数量的恶意验证查询,即它实现了(强)不可伪造性。最后,我们正式定义了VHE,并给出了基于同态加密和HEA的VHE的通用构造。通过实例化通用结构,我们推导出具有弱可验证性的完全 VHE 以及具有(强)可验证性的线性 VHE。
On one hand, homomorphic encryption allows a cloud server to perform computation on outsourced encrypted data but provides no verifiability that the computation is correct. On the other hand, homomorphic authenticator, such as homomorphic signature with public verifiability and homomorphic MAC with private verifiability, guarantees authenticity of computation over outsourced data but does not provide data confidentiality. Since cloud servers are usually operated by third-party providers which are almost certain to be outside the trust domain of cloud users, neither homomorphic encryption nor homomorphic authenticator suffices for verifiable computation on outsourced encrypted data in the cloud. In this paper, we proposeverifiablehomomorphic encryption (VHE), which enablesverifiablecomputation on outsourced encrypted data.We first introduce a new cryptographic primitive called homomorphic encrypted authenticator (HEA), which may be of independent interest. Informally, HEA can be viewed as a homomorphic authenticator in which the authenticator itself does not leak any information about the message it authenticates. Next, we show that thefullyhomomorphic MAC scheme, proposed by Gennaro and Wichs recently, is afullyHEA withweakunforgeability in the sense that an adversary is not allowed to make verification queries. We then propose alinearlyHEA which can tolerateanynumber of malicious verification queries, i.e., it achieves (strong) unforgeability. Finally, we define VHE formally, and give a generic construction of VHE based on homomorphic encryption and HEA. Instantiating the generic construction, we derive afullyVHE withweakverifiability as well as alinearlyVHE with (strong) verifiability.