Cargando…

Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things

With the rapid development of informatization, an increasing number of industries and organizations outsource their data to cloud servers, to avoid the cost of local data management and to share data. For example, industrial Internet of things systems and mobile healthcare systems rely on cloud comp...

Descripción completa

Detalles Bibliográficos
Autores principales: Wu, Bin, Wang, Caifen, Yao, Hailong
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7144983/
https://www.ncbi.nlm.nih.gov/pubmed/32271788
http://dx.doi.org/10.1371/journal.pone.0230722
_version_ 1783519919504097280
author Wu, Bin
Wang, Caifen
Yao, Hailong
author_facet Wu, Bin
Wang, Caifen
Yao, Hailong
author_sort Wu, Bin
collection PubMed
description With the rapid development of informatization, an increasing number of industries and organizations outsource their data to cloud servers, to avoid the cost of local data management and to share data. For example, industrial Internet of things systems and mobile healthcare systems rely on cloud computing’s powerful data storage and processing capabilities to address the storage, provision, and maintenance of massive amounts of industrial and medical data. One of the major challenges facing cloud-based storage environments is how to ensure the confidentiality and security of outsourced sensitive data. To mitigate these issues, He et al. and Ma et al. have recently independently proposed two certificateless public key searchable encryption schemes. In this paper, we analyze the security of these two schemes and show that the reduction proof of He et al.’s CLPAEKS scheme is incorrect, and that Ma et al.’s CLPEKS scheme is not secure against keyword guessing attacks. We then propose a channel-free certificateless searchable public key authenticated encryption (dCLPAEKS) scheme and prove that it is secure against inside keyword guessing attacks under the enhanced security model. Compared with other certificateless public key searchable encryption schemes, this scheme has higher security and comparable efficiency.
format Online
Article
Text
id pubmed-7144983
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-71449832020-04-14 Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things Wu, Bin Wang, Caifen Yao, Hailong PLoS One Research Article With the rapid development of informatization, an increasing number of industries and organizations outsource their data to cloud servers, to avoid the cost of local data management and to share data. For example, industrial Internet of things systems and mobile healthcare systems rely on cloud computing’s powerful data storage and processing capabilities to address the storage, provision, and maintenance of massive amounts of industrial and medical data. One of the major challenges facing cloud-based storage environments is how to ensure the confidentiality and security of outsourced sensitive data. To mitigate these issues, He et al. and Ma et al. have recently independently proposed two certificateless public key searchable encryption schemes. In this paper, we analyze the security of these two schemes and show that the reduction proof of He et al.’s CLPAEKS scheme is incorrect, and that Ma et al.’s CLPEKS scheme is not secure against keyword guessing attacks. We then propose a channel-free certificateless searchable public key authenticated encryption (dCLPAEKS) scheme and prove that it is secure against inside keyword guessing attacks under the enhanced security model. Compared with other certificateless public key searchable encryption schemes, this scheme has higher security and comparable efficiency. Public Library of Science 2020-04-09 /pmc/articles/PMC7144983/ /pubmed/32271788 http://dx.doi.org/10.1371/journal.pone.0230722 Text en © 2020 Wu et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Wu, Bin
Wang, Caifen
Yao, Hailong
Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title_full Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title_fullStr Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title_full_unstemmed Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title_short Security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based Internet of things
title_sort security analysis and secure channel-free certificateless searchable public key authenticated encryption for a cloud-based internet of things
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7144983/
https://www.ncbi.nlm.nih.gov/pubmed/32271788
http://dx.doi.org/10.1371/journal.pone.0230722
work_keys_str_mv AT wubin securityanalysisandsecurechannelfreecertificatelesssearchablepublickeyauthenticatedencryptionforacloudbasedinternetofthings
AT wangcaifen securityanalysisandsecurechannelfreecertificatelesssearchablepublickeyauthenticatedencryptionforacloudbasedinternetofthings
AT yaohailong securityanalysisandsecurechannelfreecertificatelesssearchablepublickeyauthenticatedencryptionforacloudbasedinternetofthings