Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud Data

Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud Data
复制标题

DOI:
10.1109/tcc.2017.2709318
复制
发表时间:
2017-05
影响因子:
6.5
通讯作者:
H. Yin;Zheng Qin;Jixin Zhang;L. Ou;Keqin Li
H. Yin;Zheng Qin;Jixin Zhang;L. Ou;Keqin Li
中科院分区:
计算机科学2区
文献类型:
--
作者:
H. Yin;Zheng Qin;Jixin Zhang;L. Ou;Keqin Li

文献摘要

被引文献

相似文献

加密云数据上的安全搜索技术允许授权用户以保护隐私的方式向云服务器提交加密的查询关键字,从而查询感兴趣的数据文件。但在实际操作中,在不诚实的云环境中,返回的查询结果可能不正确或不完整。例如,云服务器可能有意省略一些合格的结果,以节省计算资源和通信开销。因此,一个功能良好的安全查询系统应该提供查询结果验证机制,允许数据用户验证结果。本文设计了一种安全、易集成、细粒度的查询结果验证机制,给定一个加密的查询结果集,查询用户不仅可以验证查询结果集中每个数据文件的正确性,还可以进一步检查在解密前如果查询结果集不完整,有多少或哪些符合条件的数据文件没有返回。验证方案与具体的安全搜索技术是松耦合的,可以很容易地集成到任何安全查询方案中。我们通过构建加密云数据的安全验证对象来实现这一目标。提出了一种存储成本极低的短签名技术来保证验证对象的真实性,并提出了一种验证对象请求技术,使查询用户能够安全地获取所需的验证对象。性能评估表明,所提出的方案是切实可行的。
Secure search techniques over encrypted cloud data allow an authorized user to query data files of interest by submitting encrypted query keywords to the cloud server in a privacy-preserving manner. However, in practice, the returned query results may be incorrect or incomplete in the dishonest cloud environment. For example, the cloud server may intentionally omit some qualified results to save computational resources and communication overhead. Thus, a well-functioning secure query system should provide a query results verification mechanism that allows the data user to verify results. In this paper, we design a secure, easily integrated, and fine-grained query results verification mechanism, by which, given an encrypted query results set, the query user not only can verify the correctness of each data file in the set but also can further check how many or which qualified data files are not returned if the set is incomplete before decryption. The verification scheme is loose-coupling to concrete secure search techniques and can be very easily integrated into any secure query scheme. We achieve the goal by constructing secure verification object for encrypted cloud data. Furthermore, a short signature technique with extremely small storage cost is proposed to guarantee the authenticity of verification object and a verification object request technique is presented to allow the query user to securely obtain the desired verification object. Performance evaluation shows that the proposed schemes are practical and efficient.