On the Security of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-Owner Setting

被引:7
|
作者
Sun, Jianfei [1 ]
Xiong, Hu [1 ]
Nie, Xuyun [1 ]
Zhang, Yinghui [1 ,2 ]
Wu, Pengfei [1 ,3 ]
机构
[1] Univ Elect & Sci Technol China, Sch Informat & Software Engn, Chengdu 610051, Sichuan, Peoples R China
[2] Xian Univ Post & Telecommun, Xian 710121, Shaanxi, Peoples R China
[3] Peking Univ, Sch Software & Microelect, Beijing 102600, Peoples R China
关键词
Indexes; Keyword search; Encryption; Data mining; Public key; Attribute based keyword search; offline keyword guessing attacks; security vulnerabilities;
D O I
10.1109/TDSC.2019.2953744
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recently in the IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2019.28976752019), Miao et al. proposed a novel construction of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner Setting (ABKS-SM), which can delegate keyword search tasks to cloud server provider (CSP) without revealing any useful information. Although the authors claimed that the offline keyword guessing attacks can be resisted in ABKS-SM scheme, we show that this scheme indeed suffers from four types of offline keyword guessing attacks and hence fails to gain the claimed security property, which is an important goal to be achieved in searchable encryption schemes. Specifically, given the concrete attacks, we demonstrate that the underlying keyword information can be extracted from both encrypted keyword indexes and trapdoors by any malicious user and any adversarial CSP. We hope that the similar security vulnerabilities could be avoided in the future design of related searchable encryption schemes.
引用
收藏
页码:2518 / 2519
页数:2
相关论文
共 50 条
  • [41] Security Analysis of a Privacy-Preserving Decentralized Key-Policy Attribute-Based Encryption Scheme
    Ge, Aijun
    Zhang, Jiang
    Zhang, Rui
    Ma, Chuangui
    Zhang, Zhenfeng
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2013, 24 (11) : 2319 - 2321
  • [42] A privacy-preserving multi-keyword search approach in cloud computing
    Ahmed M. Manasrah
    Mahmoud Abu Nasir
    Maher Salem
    [J]. Soft Computing, 2020, 24 : 5609 - 5631
  • [43] Privacy-Preserving and Trusted Keyword Search for Multi-Tenancy Cloud
    Zhu, Xiaojie
    Shen, Peisong
    Dai, Yueyue
    Xu, Lei
    Hu, Jiankun
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 4316 - 4330
  • [44] A privacy-preserving multi-keyword search approach in cloud computing
    Manasrah, Ahmed M.
    Abu Nasir, Mahmoud
    Salem, Maher
    [J]. SOFT COMPUTING, 2020, 24 (08) : 5609 - 5631
  • [45] A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks
    Guo, Linke
    Zhang, Chi
    Sun, Jinyuan
    Fang, Yuguang
    [J]. IEEE TRANSACTIONS ON MOBILE COMPUTING, 2014, 13 (09) : 1927 - 1941
  • [46] Privacy-preserving Multi-authority Attribute-based Encryption with Dynamic Policy Updating in PHR
    Yan, Xixi
    Ni, Hao
    Liu, Yuan
    Han, Dezhi
    [J]. COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2019, 16 (03) : 831 - 847
  • [47] Privacy-Preserving Attribute-Based Encryption Supporting Expressive Access Structures
    Zhang, Liangxuan
    Li, Hui
    Zhang, Yinghui
    Khan, Fawad
    [J]. 2017 IEEE SECOND INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC), 2017, : 475 - 482
  • [48] A Privacy-Preserving Attribute-Based Reputation System in Online Social Networks
    Linke Guo
    Chi Zhang
    Yuguang Fang
    Phone Lin
    [J]. Journal of Computer Science and Technology, 2015, 30 : 578 - 597
  • [49] Privacy-Preserving Attribute-Based Credentials in Cooperative Intelligent Transport Systems
    Neven, Gregory
    Baldini, Gianmarco
    Camenisch, Jan
    Neisse, Ricardo
    [J]. 2017 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2017, : 131 - 138
  • [50] A privacy-preserving attribute-based framework for IoT identity lifecycle management
    Garcia-Rodriguez, Jesus
    Skarmeta, Antonio
    [J]. COMPUTER NETWORKS, 2023, 236