Multi-Client Sub-Linear Boolean Keyword Searching for Encrypted Cloud Storage with Owner-Enforced Authorization

Multi-Client Sub-Linear Boolean Keyword Searching for Encrypted Cloud Storage with Owner-Enforced Authorization
复制标题

DOI:
10.1109/tdsc.2020.2968425
复制
发表时间:
2021-11
影响因子:
7.3
通讯作者:
Kai Zhang;M. Wen;R. Lu;Kefei Chen
Kai Zhang;M. Wen;R. Lu;Kefei Chen
中科院分区:
计算机科学2区
文献类型:
--
作者:
Kai Zhang;M. Wen;R. Lu;Kefei Chen

文献摘要

被引文献

相似文献

到目前为止,云计算已经成为为用户提供远程数据存储服务的主要工具,因为这样用户就可以从繁琐的文档维护中解脱出来。尽管数据外包带来了好处,但意想不到的数据泄露引发了人们对数据机密性和隐私的担忧。要解决这一问题,一个简单而令人信服的策略是在将数据外包到云之前对数据进行加密。然而,由于数据加密带来的障碍,对外包加密数据的安全共享和搜索已成为一项挑战。为了应对这一挑战,本文提出了一种新的用于加密云存储的高度可扩展的可搜索加密方案。该方案实现了次线性布尔关键字搜索,并允许数据所有者授权哪些客户端可以搜索或访问云中的文档。在技术上,我们通过非平凡地将可搜索对称加密原语与一种新的访问控制技术相结合来重新审视可搜索对称加密原语,并为基于属性的访问控制和次线性搜索过程构建倒排索引数据结构。在此基础上,给出了系统的形式化安全定义,并在基于仿真的安全模型中证明了其安全性。最后,我们在一个具有代表性的真实数据集上进行了几个实验,以表明该方法的实用性。
To date, cloud computing has emerged as a primary utility for providing remote data storage services for users, since users can thus be relieved from cumbersome document maintenance. Despite of the benefits brought by data outsourcing, the unexpected data breaches raise concerns about data confidentiality and privacy. To deal with this, a straightforward and convincing strategy is to encrypt data before outsourcing them to the cloud. However, securely sharing and searching over outsourced encrypted data has turned into a challenge due to the hindrance led by data encryption. To address the challenge, this article proposes a new highly-scalable searchable encryption scheme for encrypted cloud storage. The scheme achieves sub-linear Boolean keyword searching, and moreover allows the data owner to authorize which clients could search or access the documents in the cloud. Technically, we revisit searchable symmetric encryption primitive by non-trivially combining it with a novel access control technique, and build an inverted index data structure for both attribute-based access control and sub-linear search process. Furthermore, we introduce a formalized security definition for the system, and prove its security in the simulation-based security model. Finally, we conduct a couple of experiments over a representative real-world dataset to show practicality.