Practical Attribute-Based Multi-keyword Search Scheme with Sensitive Information Hiding for Cloud Storage Systems
摘要
Attribute-based multi-keyword search (ABMKS) facilitates searching with fine-grained access control over outsourced ciphertexts. However, two critical issues impede wide application of ABMKS. Firstly, the majority of ABMKS schemes have suffered huge computation and communication costs in the process of ciphertexts matching and transmission. Secondly, the contents of data file containing sensitive information are encrypted as a whole, and data users with varying roles should have different access rights to the ciphertext returned by cloud, thereby preventing sensitive information in data files from being leaked to semi-trusted data users. In this paper, we tackle the issue of content access rights by introducing sensitive information hiding, a novel concept in the field of attribute-based keyword search. Specifically, we propose a practical multi-keyword search scheme with sensitive information hiding by integrating a modified blindness filtering technique into ciphertext policy attribute-based encryption under the multi-keyword search model. To minimize communication costs in the ciphertext transmission process, we utilize a super-increasing sequence to aggregate multiple blinding data blocks into a single ciphertext. The ciphertext can be recovered by using a recursive algorithm. Security analysis proves that our scheme is provably secure within the random oracle model, it guarantees keyword secrecy and selective security against chosen-keyword attacks. Performance evaluations demonstrate that our scheme surpasses state-of-the-art ABMKS schemes, making it highly suitable for cloud storage systems.