Proxy-Free Public-Key Authenticated Updatable and Searchable Encryption for Cloud Storage
Hongbo Li, Willy Susilo, Jian Shen, Chen Wang, Leixiao Cheng, Qiong Huang · IEEE Transactions on Dependable and Secure Computing · 2025
Public key authenticated encryption with keyword search (PAEKS) is a cryptographic primitive applicable in cloud storage systems. It empowers cloud servers to conduct searches on encrypted data without decryption while safeguarding against the brute-force attack known as insider-keyword-guessing attacks (IKGAs). In contrast to the pioneering primitive PEKS, which is vulnerable to IKGAs, PAEKS incurs additional computational and communication overhead due to the sender keys' involvement in encryption and trapdoor-generation processes. Although the recent work improves the efficiency of PAEKS by re-encrypting received ciphertexts, the requirement of a fully trusted proxy is rather costly for users to implement in practice. To reduce the economic cost and to keep a high efficiency, we propose a new primitive ofProxy-free Public-key Authenticated Updatable and Searchable Encryption(PF-AUKS). The key concept is to let the cloud server, instead of the proxy, directly convert different-source ciphertexts into a uniform format securely. We propose a concrete PF-AUKS scheme that supports fast search, constant trapdoor generation, and secure ciphertext update. Theoretical evaluation and experimental results illustrate high algorithm running speed and retrieval efficiency. We formally define the security model of PF-AUKS and prove that our scheme is secure under this model.