Abstract

Nowadays the data of the industrial Internet of Things (IIOT) have been stored in cloud servers. The security and privacy of stored data have been hot research topics. The technique of public key searchable encryption (PKSE) may contribute to protect the privacy of industrial data. It is extremely significant how to use PKSE to encrypted data and retrieve the encrypted data without revealing users’ private information. Meanwhile, most of the existing PKSE schemes do not consider the identity verification of the data owner who may upload bad ciphertext if he is malicious. In this paper, we firstly analyze the security of a certificateless searchable encryption scheme in the IIOT environment (Ma et al. scheme), and propose a feasible attack to demonstrate that their scheme is not secure. Through this attack, Type I adversary $A_{\mathrm {I}}$ can forge the trapdoor value for all keywords. Then we proposed a verifiable certificateless public key searchable encryption (VCLPKSE) scheme. The scheme not only overcomes the security issue of Ma et al. scheme, but also offers the authentications of data owners and data users. Via the authentication mechanism, data owners could not repudiate the fact they uploaded the ciphertext. Finally, we proved that the VCLPKSE scheme satisfies the ciphertext indistinguishability, trapdoor indistinguishability and unforgeability in the random oracle model. Meanwhile, we also do the simulation experiment to demonstrate the scheme’s efficiency.

Highlights

  • The Internet of Things (IOT) collects and exchanges information through wireless sensors, actuators and smart devices

  • We propose a verifiable certificateless public key searchable encryption (VCLPKSE) scheme

  • When a user authorized by the data owner wants to get the data with a specified keyword, he/she should generate a trapdoor associated with that specified keyword and sent them to cloud server

Read more

Summary

INTRODUCTION

The Internet of Things (IOT) collects and exchanges information through wireless sensors, actuators and smart devices. The owner or equipment can encrypt the data of IIOT and upload the ciphertext to cloud servers. If authorized users want to retrieve the data, they should generate and send the trapdoor information corresponding to the keyword to the cloud server. In 2000, Song et al [2] firstly proposed the concept of SSE, in which the user has to negotiate a shared key with the sender before retrieving the encrypted data. We propose a verifiable certificateless public key searchable encryption (VCLPKSE) scheme. When a user authorized by the data owner wants to get the data with a specified keyword, he/she should generate a trapdoor associated with that specified keyword and sent them to cloud server. In 2018, Ma et al [4] proposed a certificateless public key searchable encryption (CLPKSE) scheme, which is the

OUR CONTRIBUTIONS The main contributions of this paper are the following:
SECURITY MODEL
CIPHERTEXT INDISTINGUISHABILITY
TRAPDOOR INDISTINGUISHABILITY Theroem 2
UNFORGEABILITY Theroem 3
TRAPDOOR INDISTINGUISHABLE
UNFORGEABLITY
PERFORMANCE ANALYSIS
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call