Puncturable attribute-based encryption ( ) not only supports fine-grained access control over encrypted data, but also enables users to revoke the decryption capability for specific messages by puncturing tags, thereby achieving fine-grained forward security. It finds wide applications in scenarios such as sharing government classified documents and personal health records. However, existing schemes only support tag-by-tag puncturing, where each puncturing operation is done through key delegation, which causes the key size to grow with the number of punctured tags. This inefficiency makes impractical in scenarios that require frequent puncturing or mass revocations. To address this limitation, it is crucial to support batch puncturing of tags, i.e., the decryption capability for messages associated with multiple tags can be revoked simultaneously via a single puncture. In this work, we construct a ciphertext-policy attribute-based encryption ( - ) scheme for circuits with batch-puncturing. Notably, the size of the punctured key in our scheme is independent of the number of punctured tags, as well as the size and depth of the circuits. This is achieved by leveraging the evasive learning with errors ( ) and tensor assumptions. In addition, we observe that puncturable - can be re-stated by dual-policy ( - ) with key delegation, and generalize batch-puncturing - to provide the first lattice-based construction of - for circuits. Moreover, inspired by the observation of Agrawal and Yamada (Eurocrypt ’20), we introduce the puncturing property into optimal broadcast encryption ( ), capturing a new primitive called puncturable , which allows the receiver to securely erase sensitive messages without communicating with the authority.
Mobile cloud computing (MCC) optimizes storage and computation on resource-limited mobile devices by leveraging heterogeneous networks and robust cloud servers. However, outsourcing local data to cloud servers, which may be malicious, also raises concerns about data privacy. As a prominent solution for securing outsourced data, server-aided revocable attribute-based encryption (SR-ABE) enforces fine-grained access control over encrypted data while supporting lightweight user revocation. Yet, available SR-ABE schemes struggle in practice due to the following reasons. First, they rely on a fully trusted key generation center to manage attributes and issue long-term transformation and decryption keys. Second, they require setting up a fixed number of data users, and overlook attribute revocation. Third, they incorporate time-based revocation mechanisms that assume synchrony in the underlying network, which does not always hold in practice. This paper presents a secure and practical SR-ABE scheme for MCC that supports the decentralized generation of long-term user keys while integrating state-triggered user and attribute revocation mechanisms. The proposed SR-ABE scheme accommodates unlimited data users, minimizes the sizes of key and ciphertext updates via lazy revocation, and ensures verifiable outsourced decryption. We formally prove that the proposed SR-ABE scheme is adaptively secure, and conduct extensive experiments demonstrating its practicality.
The rapid deployment of emerging networks, such as the Internet of Things and cloud computing, has generated massive amounts of data. Data streaming is significant among these various data types due to its widespread use in many critical applications, such as gene sequencing, network intrusion detection, and stock trading. On the other hand, the continuously increased size of data streaming makes it impractical to store and manage the data locally, especially for those resource-constrained devices. Outsourcing the data streaming to cloud servers provides an ideal solution to the above storage issue. However, this raises the problem of how to guarantee the integrity of the outsourced data, as cloud servers may maliciously modify the data. To this end, the primitive of verifiable data streaming (VDS) was introduced to preserve the integrity of the outsourced data streaming, enabling data users to ensure that queried data items, including the contents and corresponding positions, are correct. Despite many proposed VDS protocols, most can only use the position index to query outsourced data streaming. Consequently, they fail to fulfill the requirements of those practical applications that need keyword queries. For example, in the setting of network intrusion detection, the data analyst would like to query all access records from the same IP address. In this paper, we extend the original VDS protocol to support keyword queries, i.e., allowing data users to retrieve outsourced data items with particular keywords. Specifically, we use a prefix tree to maintain keywords and another chameleon authentication tree to store data items. The two trees are bound together with cryptographic query proofs, ensuring the consistency between the position index and keyword queries. The proposed VDS protocol, which supports keyword queries, is proven secure in the standard model and outperforms previous VDS protocols in terms of functionality. The experimental results indicate that our proposal is also efficient and practical.
The widespread adoption of cloud storage has made secure and flexible access control for outsourced data a core requirement. Although ciphertext-policy attribute-based encryption (CP-ABE) provides robust technical support for fine-grained access control, its practical deployment requires schemes that can simultaneously balance efficient user revocation and practical key tracing capabilities. However, existing CP-ABE schemes fail to meet these demands. To close this gap, we propose RT-CP-ABE, a revocable and traceable CP-ABE scheme. That is, it allows the authority to revoke users by broadcasting public update keys, while maintaining the ability to trace malicious users. The proposed RT-CP-ABE scheme, for the first time, unifies indirect revocation and fully collusion-resistant black-box tracing in prime-order groups. We rigorously demonstrate through formal proofs that our proposal achieves selective security and black-box traceability in the random oracle model. The theoretical analysis indicates that, compared with previous schemes, our scheme features compact key and ciphertext sizes. Moreover, it maintains millisecond-level encryption and decryption latency, demonstrating strong practicality.
Data capsule provides a feasible solution for controllable data sharing, where data owners outsource their data capsules containing encrypted data and compliance-checking policies to the cloud server, and only valid users can run a compliant analysis program to process the decrypted data capsules in the Trusted Execution Environment (TEE), without obtaining the raw data. However, existing schemes cannot achieve verifiable accesses and updates, which means that malicious servers may use corrupted/old data capsules to deceive users and TEE. In this paper, we introduce the concept of Verifiable Data Capsule (VDC) for secure and controllable data sharing. Specifically, we first design a lightweight authentication tag, dubbed Locally Verifiable Chameleon Tag (LVCT), which allows the data owner to bind all data capsules to a constant-size tag and enables users to recover the local tags for validating data capsules. On this basis, we present a concrete VDC scheme that utilizes a dual-level authentication structure to realize verifiable data updates, and verifiable state updates triggered by regular access without the aid of the data owner. Furthermore, we propose an efficient trust evaluation protocol to judge the credibility of cloud servers. Finally, both security analysis and performance evaluation demonstrate the practicability of the proposed scheme.
As a promising decentralized paradigm, the verifiable and redactable blockchain offers a feasible solution for achieving authorized and controlled redaction of on-chain data. However, existing schemes suffer from rapidly expanding ledgers caused by authentication data structures and fail to strike a balance between permission supervision and redaction efficiency. In this paper, we propose a novel verifiable and redactable blockchain scheme that introduces a dual-level authentication architecture to achieve lightweight storage and permission supervision. To this end, we first design a dual-level authentication data structure that appends all blocks to a constant-size global tag, while supporting verifiable redaction and query over on-chain data. Likewise, we introduce a dual-level chameleon hash structure, which not only employs committee members holding sub-keys to redact on-chain data but also enables the certificate authority to use the master key to correct malicious redactions executed by corrupted committee members. Furthermore, we propose an efficient auditing protocol to enhance the integrity and consistency of the blockchain ledger during the process of synchronous circulation. Finally, both security analysis and performance evaluation prove that the proposed scheme is practical.
Identity-based encryption eliminates the complex certificate management overhead inherent in traditional public-key infrastructures, leading to its widespread adoption across various domains. However, this popularity also increases exposure to critical security threats, most notably private key leakage, which allows unauthorized parties to decrypt sensitive data. While existing forward-secure IBE schemes mitigate the impact of leakage through periodic key updates, they typically lack the granularity to revoke the decryption capability of individual ciphertexts instantaneously. To bridge this gap, we propose a novel cryptographic primitive, Forward-Secure Tag-Inverse Puncturable Identity-Based Encryption (FS-TIPIBE), that provides fine-grained forward security. Specifically, FS-TIPIBE incorporates two synergistic algorithms: private key puncturing and exclude-from-puncturing. The former updates private keys for specific tags to maintain forward security and generates corresponding tokens; the latter leverages these tokens to precisely control which ciphertexts are excluded from the puncturing process. This ensures that only non-expired and specifically excluded ciphertexts remain decryptable post-update. Furthermore, we propose a concrete FS-TIPIBE construction and provide formal security proofs under a standard bilinear group assumption. Both theoretical analysis and experimental validation attest to the efficiency and practical merits of the proposed scheme, making it a robust solution for systems requiring stringent forward security guarantees.
The verifiable data streaming (VDS) protocol enables clients to delegate locally generated data items (i.e., data streaming) to a semi-honest cloud server in real time while maintaining data integrity. It is built upon a chameleon authentication tree (CAT) and digital signatures. That is, a user may confirm the retrieved data item’s integrity by recomputing the hash value on its underlying CAT root and further checking a signature of this value created by the data owner. However, many lightweight application scenarios may not deploy public-key infrastructure (PKI) to support the digital signatures. Moreover, in frequently updated application scenarios such as trend analysis and stock forecasting, many new digital signatures are generated, and malicious cloud servers might return old versions of a queried outsourced data item and the corresponding signature. Consequently, maintaining those previously created signatures becomes a challenge. In this paper, to overcome these issues, we put forth a novel construction framework of VDS by introducing a redactable blockchain. Specifically, we treat the root value of the CAT as a transaction and package it to a redactable blockchain. After that, the immutability of the underlying redactable blockchain ensures the integrity of outsourced data streaming and avoids using the digital signature. Also, as the data is updated, we can update the root value of the CAT by re-editing the corresponding block. We also put a concrete VDS construction in the new framework, and formally prove its security. Theoretical compression and experimental results indicate that the proposed VDS protocol has merits in functionality and practicality.
The symmetric password-authenticated key exchange (PAKE) protocol enables two parties sharing a low-entropy password to establish a high-entropy session key, offering advantages in simplicity and efficiency. This makes it particularly suitable for Internet of Things (IoT) devices with limited computational resources, positioning it as one of the most effective security methods for authentication and key exchange in IoT environments. In this article, we analyze a recently proposed efficient symmetric PAKE protocol for IoT, identifying its vulnerability to offline dictionary attacks and its failure to meet the claimed security goals. Building upon the analysis of these design flaws, we present an enhanced protocol, demonstrating its security within the random oracle model. The enhanced protocol retains the protocol flow and computational operations of the original protocol to the greatest extent possible, maintains nearly the same computational efficiency, and simultaneously addresses the vulnerabilities that made the original protocol susceptible to offline dictionary attacks.
Due to the importance and sensitivity of medical data, the security protection and privacy preservation of the Healthcare Internet of Things (IoT) are current research hotspots. However, existing research schemes still suffer from incomplete security properties, imperfect authentication mechanisms, and inadequate privacy preservation. Therefore, this paper presents SECP-AKE, a secure and efficient certificateless-password-based authenticated key exchange protocol for IoT-based smart healthcare, which enables batch authentication, resists physical attacks, and provides strong anonymity. Specifically, using certificateless cryptography, the SECP-AKE protocol enables batch authentication of authorized users and devices while also resolving the key escrow problem. In particular, the SECP-AKE protocol incorporates Physical Unclonable Functions (PUFs) to resist physical attacks, thus enhancing device security and ensuring reliable medical service delivery. Additionally, the design of a pseudonym update mechanism can achieve user unlinkability, thereby providing enhanced privacy preservation. The results from both formal verification using SVO logic and informal security analyses demonstrate that the SECP-AKE protocol is secure and offers more comprehensive security properties. Meanwhile, the use of a well-known automated security verification tool Scyther further evaluates the protocol’s security reliability. Ultimately, comparative experiments on communication overhead and computational overhead demonstrate that the SECP-AKE protocol is efficient and feasible compared to state-of-the-art existing works.
Multi-client functional encryption (MCFE) is an extension of functional encryption (FE) in the multi-user setting and serves as a generalization of multi-input functional encryption (MIFE). The necessity of hiding function when it contains sensitive information, coupled with the widespread application of inner product (IP) in the descriptive statistics, has led to extensive research on function-hiding MCFE for IP. However, these works all rely on pairings and impose serious restrictions on the size of supported messages, as they all use inefficient decryption involving the extraction of discrete logarithms. On the other hand, although Abdalla et al. (CRYPTO 2018) introduced the first inner-product MIFE scheme for large message space as a special case of MCFE, it is not function-hiding. Consequently, existing inner-product MCFE schemes either exclusively support large space or solely achieve function-hiding, with no solution simultaneously achieving both properties. This paper employs an incremental construction strategy to design the function-hiding inner-product MCFE scheme, which does not require pairings. This leads to two main advances. First, we achieve the function hiding for inner-product MIFE even for messages of super-polynomial size. Second, we obtain the first function-hiding inner-product MCFE for large space, where the length of the message is of super-polynomial size.
Anonymous messaging system allows users to deliver messages without revealing the sending content and their identifiers, which has attracted ongoing concerns. However, to the best of our knowledge, all the existing solutions still fail to protect users' privacy under coercion. That is, the user's communication transcripts might be tracked and cached, and later coerced to reveal the underlying messages associated with the ciphertexts due to law enforcement reasons or for evil purposes. In addition, anonymity alone is not enough for some practical scenarios. For instance, a journalist just wants to communicate with those intended informants, and thereby gather information from anonymous but authenticated sources. In this paper, to address the above-mentioned issues, we introduce an authenticated and deniable anonymous messaging framework. Its core component is a new cryptographic primitive dubbed deniable identity-based matchmaking encryption (DIB-ME), which captures plausible deniability under coercion and mutual authentication without interactions simultaneously. We further present a concrete DIB-ME construction and prove its security in the random oracle model. The performance analysis indicates merits of the proposed DIB-ME scheme. We also implement the proposed DIB-ME construction and present extensive experiment results, as a proof of concept to demonstrate its soundness and practicability.
The primitive of vector commitment scheme allows a user to commit to an ordered sequence of messages (i.e., a vector) and later open the commitment at any position subset of the vector. The most important and desirable feature of vector commitment schemes is that the size of the opening proof is sublinear in the length of the committed vector. The original vector commitment scheme has now been extended to support several new functionalities like aggregation, updatability and homomorphism, and has applications ranging from verifiable data streaming to stateless cryptocurrency. Among these extensions, the linear-map vector commitment (LVC) scheme enables a user to open a general linear map evaluated on the committed vector, rather than those messages of the committed vector as in the original vector commitment scheme. However, the existing LVC schemes are only proved to be secure under the idealized assumptions, i.e., using the algebraic group model, which might be unpractical in the real world. To this end, we eliminate the use of algebraic group model, and propose a practically secure LVC construction. Our construction achieves practical security by additionally generating degree proofs for polynomials that enable a verifier to check the degree of polynomials publicly. We prove the security of the proposed LVC construction in the standard model under a q-type complexity assumption over bilinear groups. Moreover, we demonstrate how to use the proposed LVC scheme to construct maintainable vector commitments and verifiable data streaming protocols. The theoretical comparison and experimental results indicate that our proposal provides stronger security guarantee, while being competitive in terms of efficiency.
With the growing popularity of various Internet of Things (IoT) applications, securing data transmission over these networks become critical. The authenticated key exchange (AKE) protocol is a fundamental cryptographic primitive that achieves this goal by creating a shared session key. However, since IoT end devices are usually resource-constrained, devising secure and efficient AKE protocols for IoT applications remains challenging. In this paper, we investigate the design of zero round-trip time (0-RTT) session resumption protocols based on pre-shared keys, which enables an end device to send encrypted data to a server without prior key exchange. Specifically, we first propose a new construction of puncturable pseudo-random function (PRF), and prove its security under the RSA assumption. Then, based on the proposed puncturable PRF and authenticated encryption with associated data, we put forward a new construction of 0-RTT session resumption protocol that simultaneously provides forward security and resistance against replay attacks. We further demonstrate how to combine the proposed 0-RTT session resumption protocol with other symmetric AKE protocols for IoT applications. Both theoretical comparisons and experimental results indicate that our proposal has significant advantages in terms of computation and storage costs for practical parameter settings. Thus, it is especially desirable for constrained devices.
Deep neural networks, particularly convolutional neural networks, are vulnerable to adversarial examples, undermining their reliability in visual recognition tasks. Adversarial example detection is a crucial defense mechanism against such attacks but often relies on empirical observations and specialized metrics, posing challenges in terms of data efficiency, generalization to unknown attacks, and scalability to high-resolution datasets like ImageNet. To address these issues, we propose a prototypical network-based method using a deep residual network as the backbone architecture. This approach is capable of extracting discriminative features of adversarial and normal examples from various known adversarial examples by constructing few-shot adversarial detection tasks. Then the optimal mapping matrix is computed using the Sinkhorn algorithm from optimal transport theory, and the class centers are iteratively updated, enabling the detection of unknown adversarial examples across scenarios. Experimental results show that the proposed approach outperforms existing methods in the cross-adversary benchmark and achieves enhanced generalization on a subset of ImageNet in detecting both new adversarial attacks and adaptive white-box attacks. The proposed approach offers a promising solution for improving the safety of deep neural networks in practical applications.
The rapid development of both hardware and software has promoted the popularization of various real-time applications like health monitoring and intrusion detection that are widely deployed in outsourcing scenarios, e.g., mobile edge computing and cloud computing. In these applications, end devices continuously generate unbounded sequences of data items at a fast rate, i.e., the so-called streaming data. Nevertheless, storing and processing massive amounts of streaming data poses a challenge for resources-restricted end devices. Although outsourcing data items to edge servers or cloud servers is an attractive solution to the above problem, it also brings a new challenge, i.e., how to guarantee the integrity of outsourced data, since streaming data applications are usually sensitive of both location and the corresponding context, and servers are not completely trusted. To this end, the primitive of verifiable data streaming (VDS) protocol was introduced to maintain outsourced streaming data, while preserving its integrity. However, existing VDS constructions mainly use the structure of Merkle hash tree, and inherently have logarithmic costs. Consequently, they are infeasible for real-time applications that are delay sensitive and generate unpredictable size of streaming data. In this paper, we optimize previous VDS protocols from the aspects of communication overhead and computation cost. Specifically, we adopt a technical route different from Merkle hash tree, i.e, combining the digital signature with the cryptographic accumulator. In our construction, we employ Boneh-Lynn-Shacham (BLS) signature to guarantee the integrity of the context and position of each outsourced data item, and adopt an RSA accumulator to invalidate the old signature after the corresponding data item was updated. This immediately yields an optimal VDS construction that has constant costs even under concurrent queries, which is more desirable for those resource-limited mobile devices. In addition, the aggregability of BLS signature makes our VDS construction capable of data auditing, which enables the user to remotely verify the integrity of outsourced streaming data. We provide a formal security proof of the proposed VDS construction under well-studied complexity assumptions in the random oracle model. As a proof-of-concept, we also implement our proposal, and conduct extensive experiments to demonstrate its practicability.
The primitive of verifiable data streaming (VDS) provides a secure data outsourcing solution for resource-constrained users, that is, they can stream their continuously-generated data items to untrusted servers while enabling publicly verifiable query and update. However, existing VDS schemes either require the server to store the authentication tags of all data items to support data query and auditing, or bind all data items into a constant-size tag to achieve optimal storage on the server side, but cannot achieve public auditing. To close this gap, in this paper, we first design a novel authentication data structure, dubbed retrievable homomorphic verifiable tags (RHVTs), which allows users to aggregate the authentication tags of all data items into a constant-size tag, and enables them to retrieve the original tags from the aggregated tag when necessary. Based on this, we propose a compact verifiable and auditable data streaming (CVADS) scheme, which adopts a single-level authentication mechanism to achieve more efficient data append and update, as well as optimal storage and public auditing. For better robustness and performance, we introduce a nested dual-level authentication mechanism and propose a blockchain-based CVADS (BCVADS) scheme to achieve a distributed CVADS with self-auditing. Finally, we prove the security of our schemes in the random oracle model and demonstrate their practicality through a visual performance evaluation.
In various real-time applications like intelligent transportation and stock trading systems, clients continuously generate the so-called data streaming that is sensitive to both the position and content. Due to the limitations of local storage resources, clients usually have to outsource the generated data to cloud servers that are not fully trusted. The primitive of verifiable data streaming (VDS) protocol was introduced to guarantee the integrity of the outsourced data streaming. Although many VDS protocols have been proposed to improve the efficiency and security of the original one, they mainly focus on how to verifiably retrieve specific data items, without considering the requirement of retrieving aggregated results. However, such a requirement is desirable in many practical applications that only need the aggregated results of the outsourced streaming data, such as satellite cloud atlas and real-time traffic data. In this paper, we introduce a new primitive named aggregatably verifiable data streaming (AVDS) that allows a data user to retrieve aggregated results of designated data items, while guaranteeing the validity of the aggregated results. Specifically, we introduce a new authenticated data structure named chameleon linear-map vector commitment (CLVC), and also provide a concrete construction. Furthermore, we propose a general framework of AVDS protocols from the building block of CLVC. The proposed AVDS protocol is proven to be secure in the standard model. Theoretical analysis and experimental results indicate that the proposed AVDS protocol extends previous VDS protocols in terms of functionality while having comparable computation and communication overhead.
Multi-signature schemes have attracted considerable attention in recent years due to their popular applications in PoS blockchains. However, the use of general multi-signature schemes poses a critical threat to the security of PoS blockchains once signing keys get corrupted. That is, after an adversary obtains enough signing keys, it can break the immutable nature of PoS blockchains by forking the chain and modifying the history from some point in the past. Forward-secure multi-signature (FS-MS) schemes can overcome this issue by periodically updating signing keys. The only FS-MS construction currently available is Drijvers et al's Pixel, which builds on pairing groups and only achieves forward security at the time period level. In this work, we present new FS-MS constructions that either are free from pairing or capture forward security at the individual message level (i.e., fine-grained forward security). Our first construction Pixel+ works for a maximum number of time periods T. Pixel+ signatures consist of only one group element, and can be verified using two exponentiations. It is the first FS-MS from RSA assumption, and has 3.5x and 22.8x faster signing and verification than Pixel, respectively. Our second FS-MS construction Pixel++ is a pairing-based one. It immediately revokes the signing key's capacity of re-signing the message after creating a signature on this message, rather than at the end of the current time period. Thus, it provides more practical forward security than Pixel. On the other hand, Pixel++ is almost as efficient as Pixel in terms of signing and verification. Both Pixel+ and Pixel++ allow for non-interactive aggregation of signatures from independent signers and are proven to be secure in the random oracle model. In addition, they also support the aggregation of public keys, significantly reducing the storage overhead on PoS blockchains. We demonstrate how to integrate Pixel+ and Pixel++ into PoS blockchains. As a proof-of-concept, we provide implementations of Pixel+ and Pixel++, and conduct several representative experiments to show that Pixel+ and Pixel++ have good concrete efficiency and are practical.