Query Integrity Meets Blockchain: A Privacy-Preserving Verification Framework for Outsourced Encrypted Data

Query Integrity Meets Blockchain: A Privacy-Preserving Verification Framework for Outsourced Encrypted Data
复制标题

DOI:
10.1109/tsc.2022.3199111
复制
发表时间:
2023-05
影响因子:
8.1
通讯作者:
Shunrong Jiang;Jianqing Liu;Jingwei Chen;Yiliang Liu;Liangmin Wang;Yong Zhou
Shunrong Jiang;Jianqing Liu;Jingwei Chen;Yiliang Liu;Liangmin Wang;Yong Zhou
中科院分区:
计算机科学2区
文献类型:
--
作者:
Shunrong Jiang;Jianqing Liu;Jingwei Chen;Yiliang Liu;Liangmin Wang;Yong Zhou

文献摘要

相似文献

云外包以较低的成本为数据用户提供了灵活的存储和计算服务,但也带来了云服务器不完全可信等诸多安全威胁。以前的安全外包解决方案大多假设服务器是诚实但好奇的,而恶意服务器的对手模型可能返回不正确的结果很少被探索。此外,随着可验证计算的日益普及,现有的验证方案的效率还不高,不能满足实际应用中的不同场景。在本文中,我们为对抗性云外包上下文提出了一个基于区块链的可验证搜索框架。当将加密的数据外包给云或星际文件系统(IPFS)时,我们也将加密的数据索引存储在一个去中心化的区块链(即本文中的以太坊)中,该区块链是公开的,不可修改。用户获得授权后,无需数据所有者在线,即可通过预部署的智能合约灵活获取查询结果,高效检查查询完整性。此外,为了保护用户的隐私,我们构建了一个隐形授权方案,在不泄露用户身份的情况下交付访问授权。最后,通过理论分析和性能评估,验证了所提框架的安全性和有效性。
Cloud outsourcing provides flexible storage and computation services for data users in a low cost, but it brings many security threats as the cloud server may not be fully trusted. Previous secure outsourcing solutions mostly assume that the server is honest-but-curious while the adversary model of a malicious server that may return incorrect results is rarely explored. Moreover, with the increasing popularity of verifiable computations, existing verification schemes are yet not efficient and cannot cater to different scenarios in practice. In this paper, we propose a blockchain-based verifiable search framework for the adversarial cloud outsourcing context. When outsourcing the encrypted data to the cloud or Interplanetary File System (IPFS), we also store the encrypted data index in a decentralized blockchain (i.e., Ethereum in this paper) which is public and cannot be modified. Once a user is authorized, he/she can flexibly obtain the query results and efficiently check the query integrity via the pre-deployed smart contract, without the need of the data owner being online. Moreover, for user's privacy protection, we construct a stealth authorization scheme to deliver the access authorization without any identity disclosure. Finally, theoretical analysis and performance evaluation validate the security and efficiency of our proposed framework.