跳到主要內容

簡易檢索 / 詳目顯示

研究生: 張昌智
Chang, Chang-Chih
論文名稱: 具可否認性與表達性之模組化可搜尋加密框架
Modular Framework for Deniable and Expressive Searchable Encryption
指導教授: 曾一凡
Tseng, Yi-Fan
口試委員: 林志訓
Lin, Chih-Hsun
劉子源
Liu, Zi-Yuan
學位類別: 碩士
Master
系所名稱: 資訊學院 - 資訊科學系碩士在職專班
Excutive Master Program of Computer Science
論文出版年: 2026
畢業學年度: 115
語文別: 英文
論文頁數: 48
中文關鍵詞: 可否認加密可搜尋加密公開金鑰可搜尋加密身分基加密
外文關鍵詞: Deniable Encryption, Searchable Encryption, PEKS, IBE
相關次數: 點閱:46下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 近年來雲端運算的快速發展,使得將資料上傳至雲端伺服器已成為現代資訊系統的常見模式。然而,在確保資料機密性的同時仍允許伺服器對加密資料進行搜尋,成為一項挑戰。可搜尋加密(Searchable Encryption)技術允許使用者在不解密資料的情況下執行查詢,但多數既有機制並未考慮使用者在脅迫情境下可能被迫揭露搜尋憑證或查詢內容的問題。
    為了解決此問題,本研究提出一個通用的「可否認可搜尋加密(Deniable Searchable Encryption, DSE)」框架。我們將「公開金鑰可搜尋加密(Public Key Encryption with Keyword Search, PEKS)」抽象為一個滿足「選擇關鍵字攻擊安全性(Indistinguishability against Chosen Keyword Attack, IND-CKA)」的搜尋元件,並利用「身份基加密(Identity-Based Encryption, IBE)」作為否認性機制,設計一個模組化的轉換方法。透過此方法,可在不犧牲效率的情況下,將任一具 IND-CKA 安全性的具表達性 PEKS 機制轉換為具備抵抗脅迫能力的搜尋加密系統。
    我們並證明,若底層 PEKS 滿足 IND-CKA 安全性且 IBE 滿足匿名選擇明文攻擊安全性(Anonymous Indistinguishability under Chosen Plaintext Attack, ANON-CPA),則所提出的 DSE 建構可同時達成關鍵字隱私與抵抗脅迫之否認性。


    Recent rapid advances in cloud computing have made uploading data to cloud servers a common practice in modern information systems. However, allowing servers to perform searches over encrypted data while ensuring data confidentiality remains a challenge. Searchable Encryption (SE) enables users to perform queries without decrypting the data, but most existing schemes do not consider scenarios in which users may be forced to reveal search credentials or query contents under coercion.
    To address this issue, this study proposes a generic framework for Deniable Searchable Encryption (DSE). We abstract Public Key Encryption with Keyword Search (PEKS) as a search component that satisfies Indistinguishability against Chosen Keyword Attack (IND-CKA) security, and use Identity-Based Encryption (IBE) as the deniability mechanism to design a modular transformation method. Through this method, any expressive PEKS scheme that satisfies IND-CKA security can be transformed into a searchable encryption system with coercion resistance without sacrificing efficiency.
    We further prove that if the underlying PEKS satisfies IND-CKA security and the IBE satisfies Anonymous Indistinguishability under Chosen Plaintext Attack (ANON-CPA) security, then the proposed DSE construction simultaneously achieves keyword privacy and coercion-resistant deniability.

    1 Introduction 1
    1.1 Background 1
    1.2 Our Approach 4
    1.3 Contributions 5
    1.4 Organization 6
    2 Preliminaries 9
    2.1 Notations 9
    2.2 Bilinear Maps 10
    2.3 Public-Key Encryption with Keyword Search 10
    2.4 Identity-Based Encryption 11
    2.5 Deniable Searchable Encryption 13
    3 The Proposed Scheme 17
    3.1 Idea 18
    3.2 Construction 19
    4 Security Analysis 23
    4.1 IND-CKA Security 23
    4.2 ANON-CPA Security 25
    5 Comparisons 29
    5.1 Concrete Instantiation 29
    5.2 Performance Comparison 32
    6 Conclusion 43
    Bibliography 45

    [ABB10] S. Agrawal, D. Boneh, and X. Boyen, “Efficient Lattice (H)IBE in the Standard Model,” in Advances in Cryptology – EUROCRYPT 2010, ser. Lecture Notes in Computer Science, vol. 6110, Springer, 2010, pp. 553–572 (cit. pp. 3, 4, 6, 44).
    [ABC+08] M. Abdalla, M. Bellare, D. Catalano, et al., “Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions,” Journal of Cryptology, vol. 21, no. 3, pp. 350–391, 2008 (cit. p. 2).
    [AFG+10] M. Armbrust, A. Fox, R. Griffith, et al., “A View of Cloud Computing,” Communications of the ACM, vol. 53, no. 4, pp. 50–58, 2010 (cit. p. 1).
    [AG09] G. Ateniese and P. Gasti, “Universally Anonymous IBE Based on the Quadratic Residuosity Assumption,” in Topics in Cryptology – CT-RSA 2009, ser. Lecture Notes in Computer Science, vol. 5473, Springer, 2009, pp. 32–47 (cit. p. 5).
    [BCO+04] D. Boneh, G. D. Crescenzo, R. Ostrovsky, and G. Persiano, “Public Key Encryption with Keyword Search,” in Advances in Cryptology – EUROCRYPT 2004, ser. Lecture Notes in Computer Science, vol. 3027, Springer, 2004, pp. 506–522 (cit. p. 2).
    [BF01] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing,” in Advances in Cryptology – CRYPTO 2001, ser. Lecture Notes in Computer Science, vol. 2139, Springer, 2001, pp. 213–229 (cit. p. 11).
    [BHJ+14] C. Bösch, P. Hartel, W. Jonker, and A. Peter, “A Survey of Provably Secure Searchable Encryption,” ACM Computing Surveys, vol. 47, no. 2, pp. 1–51, 2014 (cit. p. 2).
    [BOY20] R. Behnia, M. O. Ozmen, and A. A. Yavuz, “Lattice-Based Public Key Searchable Encryption from Experimental Perspectives,” IEEE Transactions on Dependable and Secure Computing, vol. 17, no. 6, pp. 1269–1282, 2020 (cit. pp. 3, 4, 6).
    [BW06] X. Boyen and B. Waters, “Anonymous Hierarchical Identity-Based encryption (without random oracles),” in Advances in Cryptology – CRYPTO 2006, ser. Lecture Notes in Computer Science, vol. 4117, Springer, 2006, pp. 290– 307 (cit. pp. 5, 29, 35, 38–40).
    [BW07] D. Boneh and B. Waters, “Conjunctive, Subset, and Range Queries on Encrypted Data,” in Theory of Cryptography Conference (TCC), ser. Lecture Notes in Computer Science, vol. 4392, Springer, 2007, pp. 535–554 (cit. pp. 2, 5).
    [CC21] P.-W. Chi and Y.-L. Chang, “Do not ask me what I am looking for: Index
    deniable encryption,” Future Generation Computer Systems, vol. 122, pp. 28–
    39, 2021 (cit. p. 3).
    [CDN+97] R. Canetti, C. Dwork, M. Naor, and R. Ostrovsky, “Deniable Encryption,” in Advances in Cryptology – CRYPTO ’97, ser. Lecture Notes in Computer Science, vol. 1294, Springer, 1997, pp. 90–104 (cit. pp. 3, 6, 13).
    [CGK+06] R. Curtmola, J. Garay, S. Kamara, and R. Ostrovsky, “Searchable Symmetric Encryption: Improved Definitions and Efficient Constructions,” in Proceedings of the 13th ACM Conference on Computer and Communications Security, ser. CCS ’06, ACM, 2006, pp. 79–88 (cit. p. 2).
    [CW21] P.-W. Chi and M.-H. Wang, “Deniable Search of Encrypted Cloud-Storage Data,” Journal of Information Security and Applications, vol. 58, p. 102 806, 2021 (cit. pp. 3, 5–7, 13, 29, 32, 36, 40).
    [Gen06] C. Gentry, “Practical Identity-Based Encryption Without Random Oracles,” in Advances in Cryptology – EUROCRYPT 2006, ser. Lecture Notes in Computer Science, vol. 4004, Springer, 2006, pp. 445–464 (cit. p. 5).
    [GPV08] C. Gentry, C. Peikert, and V. Vaikuntanathan, “Trapdoors for Hard Lattices and New Cryptographic Constructions,” in Proceedings of the 40th Annual ACM Symposium on Theory of Computing (STOC), ACM, 2008, pp. 197–206 (cit. pp. 3, 4, 6, 44).
    [Gui13] A. Guillevic, “Comparing the Pairing Efficiency over Composite-Order and Prime-Order Elliptic Curves,” in Applied Cryptography and Network Security (ACNS), ser. Lecture Notes in Computer Science, vol. 7954, Springer, 2013, pp. 357–372 (cit. pp. 33, 34, 36).
    [JC22] Z. Jiang and S. Chen, “Dual Fine-Grained Public-Key Searchable Encryption from Lattices,” Computer and Information Science, vol. 15, no. 1, pp. 66–80, 2022 (cit. pp. 3, 4, 6, 44).
    [JG11] W. Jansen and T. Grance, “Guidelines on Security and Privacy in Public Cloud Computing,” National Institute of Standards and Technology (NIST), Gaithersburg, MD, USA, Tech. Rep. NIST Special Publication 800-144, 2011 (cit. p. 1).
    [KSW13] J. Katz, A. Sahai, and B. Waters, “Predicate Encryption Supporting Disjunctions, Polynomial Equations, and Inner Products,” Journal of Cryptology, vol. 26, no. 2, pp. 191–224, 2013 (cit. pp. 2, 5).
    [LZD+13] J. Lai, X. Zhou, R. H. Deng, Y. Li, and K. Chen, “Expressive Search on Encrypted Data,” in Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security, ser. ASIA CCS ’13, ACM, 2013, pp. 243–252 (cit. p. 5).
    [MG11] P. Mell and T. Grance, “The NIST Definition of Cloud Computing,” National Institute of Standards and Technology (NIST), Gaithersburg, MD, USA, Tech. Rep. NIST Special Publication 800-145, 2011 (cit. p. 1).
    [OPW11] A. O’Neill, C. Peikert, and B. Waters, “Bi-Deniable Public-Key Encryption,” in Advances in Cryptology – CRYPTO 2011, ser. Lecture Notes in Computer Science, vol. 6841, Springer, 2011, pp. 525–542 (cit. p. 3).
    [SLL20] C. Shen, Y. Lu, and J. Li, “Expressive Public-Key Encryption with Keyword Search: Generic Construction from KP-ABE and an Efficient Scheme over Prime-Order Groups,” IEEE Access, vol. 8, pp. 93–103, 2020 (cit. pp. 2, 5,
    29).
    [SWP00] D. X. Song, D. Wagner, and A. Perrig, “Practical Techniques for Searches on Encrypted Data,” in Proceedings of the 2000 IEEE Symposium on Security and Privacy, 2000, pp. 44–55 (cit. p. 2).
    [TFL22] Y.-F. Tseng, C.-I. Fan, and Z.-C. Liu, “Fast Keyword Search over Encrypted Data with Short Ciphertext in Clouds,” Journal of Information Security and Applications, vol. 70, p. 103 320, 2022 (cit. pp. 5, 29, 30, 36, 38, 40).
    [WXL+20] P. Wang, T. Xiang, X. Li, and H. Xiang, “Public Key Encryption with Conjunctive Keyword Search on Lattice,” Journal of Information Security and Applications, vol. 51, p. 102 433, 2020 (cit. pp. 3, 4, 6, 44).

    無法下載圖示 全文公開日期 2031/07/28
    QR CODE
    :::