Multi-Client Verifiable Encrypted Keyword Search Scheme With Authorization Over Outsourced Encrypted Data

  • Xu Yang
  • , Qiuhao Wang
  • , Saiyu Qi
  • , Ke Li
  • , Jianfeng Wang
  • , Wenjia Zhao
  • , Yong Qi

Research output: Contribution to journalArticlepeer-review

11 Scopus citations

Abstract

Data outsourcing is a key service of cloud computing. While data encryption ensures confidentiality, it limits the ability to search encrypted data. Recently, ciphertext-policy attribute-based keyword search (CP-ABKS) schemes, which combine symmetric searchable encryption (SSE) and ciphertext-policy attribute-based encryption (CP-ABE), have gained attention. However, most CP-ABKS schemes depend on an independent key management server (KMS) for key distribution, risking key leakage if the KMS is compromised. Additionally, these schemes lack secure update operations and efficient search result verification. To address these issues, we propose VKSA, a verifiable encrypted keyword search scheme with authorization for cloud-based multi-client environments. VKSA features a novel policy-hidden index for proxy-free authorized searches, a state-based secure update strategy for forward and backward security, and a delegated search result verification mechanism to ensure efficient and privacy-preserving verification. We further optimize VKSA for improved computational and enclave-storage efficiency. Security analysis and experiments confirm the security and efficiency of our schemes.

Original languageEnglish
Pages (from-to)6356-6371
Number of pages16
JournalIEEE Transactions on Network Science and Engineering
Volume11
Issue number6
DOIs
StatePublished - 2024

Keywords

  • access control
  • Cloud storage
  • encrypted keyword search
  • privacy
  • trusted hardware

Fingerprint

Dive into the research topics of 'Multi-Client Verifiable Encrypted Keyword Search Scheme With Authorization Over Outsourced Encrypted Data'. Together they form a unique fingerprint.

Cite this