Server-Aided Keyword Search Encryption With Password-Hardened Encryption

Pengyang Zhao · 2024

Public Key Encryption with Keyword Search (PEKS) is a widely adopted cryptographic scheme for retrieving encrypted data outsourced to cloud servers based on keywords. However, PEKS is susceptible to both offline and online Keyword Guessing Attacks (KGA). In this paper, We use Auxiliary Server to perform blind signing of user keywords to resist offline KGA and limit online KGA, then we introduce Password-Authenticated Encryption (PHE) as a means of authenticating users performing keyword searches. By leveraging passwords for identity verification and encryption key management, the keyword ciphertexts stored on the Storage Server undergo a secondary encryption process, ensuring that unauthorized users are unable to perform legitimate searches. Current password-based searchable encryption schemes are predominantly symmetric, often resulting in a more complex encryption workflow. Additionally, to address the computational overhead associated with exponentiation and zero-knowledge proofs in PHE-based schemes, we harness the capabilities of Intel SGX, a trusted execution environment. By offloading sensitive computational tasks related to password verification to SGX, we eliminate the need for costly exponentiation and zero-knowledge proofs, thereby enhancing the scheme's performance. This approach also achieves cross-period anonymity and addresses the issue of potential malicious auxiliary servers correlating user requests, as highlighted in Lai et al scheme. Consequently, the novel Server-aided Keyword Search with Password-hardened Encryption (SAKSPHE) we propose provides robust defense against offline KGA, restricts the feasibility of online KGA, and enables password-based user authentication alongside additional encryption of keyword ciphertexts for secure storage.

Read the paper · More papers on PaperTik