Improving the proof of “Privacy-preserving attribute-keyword based data publish-subscribe service on cloud platforms”
Shangping Wang, Qian Zhang, Yaling Zhang, Jin Dong Sun, Juanjuan Chen, Xiaoqing Sun · PLoS ONE · 2019
Most recently, Kan Yang et al. proposed an attribute-keyword based encryption scheme for data publish-subscribe service(AKPS), which is highly useful for cloud storage scenario.Unfortunately, we discover that there is a flaw in the security proof of indistinguishability of the tag and trapdoor against chosen keyword attack under the Bilinear Diffie-Hellman (BDH) assumption.As the security proof is a key component for a cryptographic scheme, based on the Decisional Diffie-Hellman (DDH) assumption, we improve the security proof method and give a new security proof of the AKPS scheme for indistinguishability of the tag and trapdoor in our proposal, which is more rigorous than the original one.Furthermore, we also demonstrate that the AKPS scheme is secure against data Replayable Chosen Ciphertext Attack (RCCA). I. IntroductionData publish-subscribe system [1,2] is an appropriate mode for data users to receive data for interest.Cloud server, owing to considerable resources on storage and calculation, has been proven to be the most applicable platform for this service [3][4][5].To realize fine-grained access control of data on cloud storage, the concept of the attributebased encryption (ABE) was proposed.Generally ABE can be divided into two categories: Ciphertext-Policy Attribute-based Encryption (CP-ABE) [6,7] and Key-Policy Attributebased Encryption (KP-ABE) [8], both are intended for one-to-many access mode.Attributebased encryption is an extension of public-key cryptography and identity-based cryptography.Compared with traditional cryptography, attribute-based encryption provides a more flexible encryption and decryption relationship.For example, in an attribute-based encryption mechanism, both the ciphertext and the secret key are associated with a set of attributes, and the data owner can specify an encryption policy consisting of attributes, and the resulting ciphertext can be decrypted only by the data user whose attributes satisfies the encryption policy.The non-interactive access control with fine-grained can be realized effectively by attribute-based encryption, which greatly enriches the flexibility of encryption policy and the description of