Zhang Jianhong, Ou Peirong
School of Information Sciences and Technology, North China University of Technology, Beijing 100144, China.
National Engineering Laboratory for Big Data Collaborative Security Technology, Beijing 100015, China.
Sensors (Basel). 2019 Jul 31;19(15):3370. doi: 10.3390/s19153370.
Nowadays, the widely deployed and high performance Internet of Things (IoT) facilitates the communication between its terminal nodes. To enhance data sharing among terminal devices and ensure the recipients' privacy protection, a few anonymous multi-recipient broadcast encryption (AMBE) proposals are recently given. Nevertheless, the majority of these AMBE proposals are only proven be securely against adaptively chosen plain-text attack (CPA) or selectively chosen ciphertext attack (CCA). Furthermore, all AMBE proposals are subjected to key escrow issue due to inherent characteristics of the ID-based public cryptography (ID-PKC), and cannot furnish secure de-duplication detection. However, for cloud storage, it is very important for expurgating duplicate copies of the identical message since de-duplication can save the bandwidth of network and storage space. To address the above problems, in the work, we present a privacy-preserving multi-receiver certificateless broadcast encryption scheme with de-duplication (PMCBED) in the cloud-computing setting based on certificateless cryptography and anonymous broadcast encryption. In comparison with the prior AMBE proposals, our scheme has the following three characteristics. First, it can fulfill semantic security notions of data-confidentiality and receiver identity anonymity, whereas the existing proposals only accomplish them by formalizing the weaker security models. Second, it achieves duplication detection of the ciphertext for the identical message encrypted with our broadcast encryption. Finally, it also avoids the key escrow problem of the AMBE schemes.
如今,广泛部署且高性能的物联网(IoT)促进了其终端节点之间的通信。为了增强终端设备之间的数据共享并确保接收者的隐私保护,最近提出了一些匿名多接收者广播加密(AMBE)方案。然而,这些AMBE方案中的大多数仅被证明能安全抵御适应性选择明文攻击(CPA)或选择性选择密文攻击(CCA)。此外,由于基于身份的公钥密码学(ID-PKC)的固有特性,所有AMBE方案都存在密钥托管问题,并且无法提供安全的去重检测。然而,对于云存储而言,去除相同消息的重复副本非常重要,因为去重可以节省网络带宽和存储空间。为了解决上述问题,在这项工作中,我们基于无证书密码学和匿名广播加密,在云计算环境中提出了一种具有去重功能的隐私保护多接收者无证书广播加密方案(PMCBED)。与先前的AMBE方案相比,我们的方案具有以下三个特点。首先,它可以实现数据保密性和接收者身份匿名性的语义安全概念,而现有方案只是通过形式化较弱的安全模型来实现这些概念。其次,它实现了对使用我们的广播加密加密的相同消息的密文的重复检测。最后,它还避免了AMBE方案的密钥托管问题。