Generic Construction of Public-key Authenticated Encryption with Keyword Search Revisited: Stronger Security and Efficient Construction

Generic Construction of Public-key Authenticated Encryption with Keyword Search Revisited: Stronger Security and Efficient Construction
复制标题

DOI:
10.1145/3494105.3526237
复制
发表时间:
2022-05
期刊:
Proceedings of the 9th ACM on ASIA Public-Key Cryptography Workshop
影响因子:
--
通讯作者:
K. Emura
K. Emura
中科院分区:
其他
文献类型:
--
作者:
K. Emura

文献摘要

相似文献

带关键字搜索的公钥加密(PEKS)不提供trapdoor隐私,即关键字信息通过trapdoor泄露。为了防止这种信息泄露,提出了使用关键字搜索的公钥认证加密(PAEKS),其中加密需要发送方的秘密密钥,并且陷阱门不仅与关键字关联,而且与发送方关联。Liu等人(ASIACCS 2022)提出了一种基于词无关光滑投影哈希函数(SPHFs)和PEKS的泛型paek构造方法。本文提出了一种新的泛型PAEKS结构。基本构建方法与Liu等人的构建方法相同,使用SPHFs将每个关键字转换为扩展关键字,扩展关键字使用PEKS。尽管如此,我们的构建比Liu等人的更高效,因为我们只使用了一个SPHF,而Liu等人使用了两个SPHF。此外,为了一致性,我们考虑了一个比Liu等人的更强的安全模型。简而言之,Liu等人只考虑关键字,尽管活板门不仅与关键字有关,而且与发送方有关。因此,与发送方关联的活板门不应该对由另一个发送方的密钥生成的密文起作用,即使关联了相同的关键字。我们的定义考虑了多发送方设置并捕获了这种情况。此外,为了对所选关键字攻击(IND-CKA)和对内部关键字猜测攻击(IND-IKGA)的不可区分性,我们使用了秦等人(ProvSec 2021)定义的更强的安全模型,其中允许攻击者查询加密和陷阱门预言的挑战关键字。我们还强调了与Liu等人在哈希函数方面的构造相关的几个问题,例如,他们的构造不满足他们声称持有的一致性。
Public-key encryption with keyword search (PEKS) does not provide trapdoor privacy, i.e., keyword information is leaked through trapdoors. To prevent this information leakage, public key authenticated encryption with keyword search (PAEKS) has been proposed, where a sender's secret key is required for encryption, and a trapdoor is associated with not only a keyword but also the sender. Liu et al. (ASIACCS 2022) proposed a generic construction of PAEKS based on word-independent smooth projective hash functions (SPHFs) and PEKS. In this paper, we propose a new generic construction of PAEKS. The basic construction methodology is the same as that of the Liu et al. construction, where each keyword is converted into an extended keyword using SPHFs, and PEKS is used for extended keywords. Nevertheless, our construction is more efficient than Liu et al.'s in the sense that we only use one SPHF, but Liu et al. used two SPHFs. In addition, for consistency we considered a security model that is stronger than Liu et al.'s. Briefly, Liu et al. considered only keywords even though a trapdoor is associated with not only a keyword but also a sender. Thus, a trapdoor associated with a sender should not work against ciphertexts generated by the secret key of another sender, even if the same keyword is associated. Our definition considers a multi-sender setting and captures this case. In addition, for indistinguishability against chosen keyword attack (IND-CKA) and indistinguishability against inside keyword guessing attack (IND-IKGA), we use a stronger security model defined by Qin et al. (ProvSec 2021), where an adversary is allowed to query challenge keywords to the encryption and trapdoor oracles. We also highlight several issues associated with the Liu et al. construction in terms of hash functions, e.g., their construction does not satisfy the consistency that they claimed to hold.