LiST \(^+\) : An Improved Lightweight Sharable and Traceable Secure Mobile Health System
摘要
Recently, in IEEE Transactions on Dependable and Secure Computing, Yang et al. [20] proposed a computationally efficient attribute-based single-keyword searchable encryption scheme (called LiST) in which patient data are encrypted end-to-end from a patient’s mobile device to data users. The authors claimed that LiST is provably secure without random oracles. However, after carefully revisiting the LiST scheme, we demonstrate that it cannot preserve data confidentiality by proposing two attacks on data confidentiality. The simulation results demonstrate that our attacks are practical. We also show that the Test and Decryption operations in the LiST scheme are incorrect. To overcome the aforementioned issues, we present a new improvement of LiST scheme (which we call LiST \(^+\) ) without compromising the original scheme’s efficiency.