As a basic primitive in spatial and multimedia databases, the $k$ -nearest neighbors ( $k$ -NN) query has been widely used in electronic medicine, location-based services and so on. With the boom in cloud computing, it is currently a trend to upload massive data to the cloud server to enjoy its powerful storage and computing resources. Recently, research communities and commercial applications have proposed many schemes to support $k$ -NN query on cloud data. However, most of the existing schemes were designed under the assumption that the query users (QUs) are fully trusted and hold the key of the data owner (DO). In this case, even if the queries were encrypted, the QUs can capture the query content from each other, leading to the query privacy leakage. Unfortunately, to the best of our knowledge, few $k$ -NN query schemes can ensure data security and result verification under the key confidentiality condition. In this paper, we propose a verifiable and privacy-preserving $k$ -NN query scheme with multiple keys (VP $k$ NN), in which each QU's partial private key can only decrypt the encrypted query results belonging to its own , but not the encrypted database, the encrypted query data and query results of other QUs. Moreover, our proposal not only answers the query efficiently, but also ensures the privacy of the data, the query and the result, and the verification of the correctness of the results. Finally, the complexity and security are theoretically analyzed, and the practicality and efficiency of our proposed scheme are compared by simulation experiments.
As a basic primitive in spatial and multimedia databases, the k-nearest neighbors (k-NN) query has been widely used in electronic medicine, location-based services, and so on. With the boom in cloud computing, it is currently a trend to upload massive data to the cloud server to enjoy its powerful storage and computing resources. Recently, research communities and commercial applications have proposed many schemes to support k-NN query on cloud data. However, most of the existing k-NN query schemes were designed under the assumption that the query users (QUs) are fully trusted and hold the key of the data owner. In this case, even if the queries were encrypted, the QUs can capture the query content from each other, leading to the query privacy leakage. Unfortunately, to the best of our knowledge, few k-NN query schemes can ensure data privacy under the key-confidentiality condition. In this article, we propose a secure k-NN query with multiple keys based on random projection forests (SMkNN), in which each QU's partial strong private key can only decrypt the encrypted query results belonging to its own, but not the encrypted database, the encrypted query data and query results of other QUs. Moreover, our proposal not only answers the query efficiently but also ensures the privacy of data, query, results, and access pattern, and the verification of the correctness of the results. Finally, the complexity and security are theoretically analyzed, and the practicality and efficiency of our proposed scheme are compared by simulation experiments. Index Terms-Access pattern
Public key encryption with equality test (PKEET) is a cryptographic primitive that enables a tester to determine whether two ciphertexts encrypted with same or different public keys have been generated from the same message without decryption. Previous studies extended PKEET to public key encryption with designated-position fuzzy equality test (PKE-DFET), enabling testers to verify whether plaintexts corresponding to two ciphertexts are equal while ignoring specific bits at designated positions. In this work, we have filled the research gap in the identity-based encryption (IBE) cryptosystems for this primitive. Furthermore, although our authorization method is the all-or-nothing (AoN) type, it overcomes the shortcomings present in the majority of AoN-type authorization schemes. In our scheme, equality tests can only be performed between a ciphertext and a given plaintext. Specifically, even if a tester acquires multiple AoN-type authorizations, it cannot conduct unpermitted equality tests between users. This significantly reduces the risk of user privacy leaks when handling sensitive information in certain scenarios, while still retaining the flexible and simple characteristics of AoN-type authorizations. We use the Chinese national cryptography standard SM9-IBE algorithm to provide the concrete construction of our scheme, enhancing the usability and security of our scheme, while making deployment more convenient. Finally, we prove that our scheme achieves F-OW-ID-CCA security when the adversary has the trapdoor of the challenge ciphertext, and achieves IND-ID-CCA security when the adversary does not have the trapdoor of the challenge ciphertext.
Private information retrieval (PIR) enables a client to search data from a single (or multiple) untrusted server, without revealing which entry was queried. PIR can be divided into two categories: information-theoretic PIR (IT-PIR) and computational PIR (CPIR). However, there is a deployment challenge with IT-PIR because the non-collusion assumption is difficult to implement in practice. Meanwhile, due to the fact that CPIR involves performing cryptographic operations on each element, its performance significantly decreases as the size and number of database entries increase. To overcome these problems, based on homomorphic encryption, this paper presents a parallel PIR (ParPIR) with index anonymity for untrusted databases, which uses the batch encoding to compress request size. Furthermore, our ParPIR eliminates computationally expensive ciphertext multiplication operations, which improves the response time. Moreover, our ParPIR packs multiple responses through rotation column operations on ciphertext, thereby reducing the response size. Compared to previous PIR protocols, the offline time in our ParPIR has almost 1∼63× improvement; the online time in our ParPIR decreases by at least 49.9∼98.9%. Meanwhile, although the request size of our ParPIR has a 0∼31× increase, the response size of our ParPIR has a 0∼4095× improvement.
Hundreds of millions of accounts are sold on the Dark Web as a result of hacking. These stolen accounts can be used to maliciously log into the victim’s application, which is also known as credential stuffing attacks. Recently, to resist these attacks, several compromised credential checking (C3) services have been deployed to provide users with APIs to check whether their accounts have been exposed. However, these C3 services provide the security at the cost of high latency and bandwidth. There is also the problem implicitly trusting the server to properly handle the hash prefixes containing passwords. To solve these problems, we present an efficient C3 protocol for account protection, which enables a client to check whether its account appears in a database storing the compromised credentials, without disclosing the queried account to the server. Compared to existing C3 services, the proposed C3 protocol has 10∼20× and 17.8∼20.7% improvement in computational time for both the client and server during the online phase, respectively, while maintaining the same computational time for server during the preprocessing phase. Meanwhile, the proposed C3 protocol improves the communication cost of client-to-server by 17∼33× while maintaining the same communication cost of server-to-client.
In the last decade, E-voting has received great attention due to its advantages in efficiency and accuracy. Fan et al. presented a novel E-voting system named HSE-Voting by utilizing homomorphic signcryption. The HSE-Voting system was claimed to gain a provable security goal under the standard proof. In this paper, we illustrate that their scheme may suffer from some potential security issues. On the one hand, the voting information could be recovered by the authentication center (AC). On the other hand, any malicious voter could disrupt the voting system undetected by locally modifying his ballot. In order to increase the resilience of the voting system to risks, an improvement of the HSE-Voting system is developed. Our improved system fixes the above security weaknesses but increases the computation cost on the AC side by a small amount. In addition, the proposed scheme satisfies voter anonymity, ballot privacy, and verifiability of election results.
The virtual dimension called `Cyberspace' built on internet technologies has served people's daily lives for decades. Now it offers advanced services and connected experiences with the developing pervasive computing technologies that digitise, collect, and analyse users' activity data. This changes how user information gets collected and impacts user privacy at traditional cyberspace gateways, including the devices carried by users for daily use. This work investigates the impacts and surveys privacy concerns caused by this data collection, namely identity tracking from browsing activities, user input data disclosure, data accessibility in mobile devices, security of delicate data transmission, privacy in participating sensing, and identity privacy in opportunistic networks. Each of the surveyed privacy concerns is discussed in a well-defined scope according to the impacts mentioned above. Existing countermeasures are also surveyed and discussed, which identifies corresponding research gaps. To complete the perspectives, three complex open problems, namely trajectory privacy, privacy in smart metering, and involuntary privacy leakage with ambient intelligence, are briefly discussed for future research directions before a succinct conclusion to our survey at the end.
Since traditional federated learning (FL) algorithms cannot provide sufficient privacy guarantees, an increasing number of approaches apply local differential privacy (LDP) techniques to FL to provide strict privacy guarantees. However, the privacy budget heavily increases proportionally with the dimension of the parameters, and the large variance generated by the perturbation mechanisms leads to poor performance of the final model. In this article, we propose a novel privacy-preserving edge FL framework based on LDP (PPeFL). Specifically, we present three LDP mechanisms to address the privacy problems in the FL process. The proposed filtering and screening with exponential mechanism (FS-EM) filters out the better parameters for global aggregation based on the contribution of weight parameters to the neural network. Thus, we can not only solve the problem of fast growth of privacy budget when applying perturbation mechanism locally but also greatly reduce the communication costs. In addition, the proposed data perturbation mechanism with stronger privacy (DPM-SP) allows a secondary scrambling of the original data of participants and can provide strong security. Further, a data perturbation mechanism with enhanced utility (DPM-EU) is proposed in order to reduce the variance introduced by the perturbation. Finally, extensive experiments are performed to illustrate that the PPeFL scheme is practical and efficient, providing stronger privacy protection while ensuring utility.
Proposing novel cryptography schemes (e.g., encryption, signatures, and protocols) is one of the main research goals in modern cryptography. In this paper, based on more than 800 research papers since 1976 that we have surveyed, we introduce the research philosophy of cryptography behind these papers. We use “benefits” and “novelty” as the keywords to introduce the research philosophy of proposing new schemes, assuming that there is already one scheme proposed for a cryptography notion. Next, we introduce how benefits were explored in the literature and we have categorized the methodology into 3 ways for benefits, 6 types of benefits, and 17 benefit areas. As examples, we introduce 40 research strategies within these benefit areas that were invented in the literature. The introduced research strategies have covered most cryptography schemes published in top-tier cryptography conferences. *This work is based on our Chinese book (Cryptologic Research History of Digital Signatures: From 1976 to 2020) that was first published in November of 2022. The research philosophy has undergone a major revision. Fuchun Guo and Willy Susilo are from the University of Wollongong, Xiaofeng Chen and Zhen Zhao are from the Xidian University, Peng Jiang is from the Beijing Institute of Technology, and Jianchang Lai is from the Southeast University. Supported by ARC Future Fellowship FT220100046 (fuchun@uow.edu.au).
In the data era, to simultaneously relieve the heavy computational burden of mining data information from data owners and protecting data privacy, privacy-preserving frequent itemset mining (PPFIM) is presented and has attracted much attention. In PPFIM, data owners and miners outsource the complex task of data mining to the cloud server, which supports strong storage and computing power, and the cloud server cannot extract additional data privacy other than that which is shown by data owners or miners. However, most existing solutions assume that cloud servers will honestly perform the mining process and return the correct results, whereas cloud services are usually provided by a charging third party that may in practice return incorrect results due to computation errors, malicious or criminal activities, etc. To solve this problem, in this paper, we present a verifiable PPFIM protocol on vertically partitioned databases to support the verifiability of the integrity of the mining results, where data owners can authorize the cloud server to perform federated mining on vertically partitioned databases without leaking data information and detect dishonest behaviors in the cloud server from the returned results. We adopt a dual cloud setting to enable data owners to be offline after uploading their encrypted databases to the cloud server, which further relieves the burden on data owners. We implement our protocol and give a detailed analysis in terms of verification accuracy, which shows that the dishonest behaviors of the cloud server can be detected with a probability close to 1 and a sacrifice of only a 1% increase in database size.
Public key encryption with equality test (PKEET) is a cryptographic primitive that enables a tester to determine, without decryption, whether two ciphertexts encrypted with different public keys generate from the same message. In previous research, public key encryption with equality test (PKEET) was extended to include identity-based encryption with equality test (IBEET), thereby broadening the application of PKEET. Subsequently, certificateless encryption with equality test (CLEET) was introduced to address the key escrow problem in IBEET. However, existing CLEET schemes suffer from inefficiency and potential information leakage when dealing with multiple ciphertexts due to the need for pairwise equality tests. To address this issue, we propose a concept of certificateless encryption supporting multi-ciphertext equality test with proxy-assisted authorization (CLE-MET-PA). CLE-MET-PA incorporates the functionality of the multi-ciphertext equality test into CLEET, enabling a tester to perform a single equality test on multiple ciphertexts to determine whether the underlying plaintexts are equal, without revealing any additional information. This enhances the security of our scheme while significantly reducing the computational overhead compared to multiple pairwise equality tests, making our scheme more efficient. Additionally, our approach integrates proxy-assisted authorization, allowing users to delegate a proxy to grant authorizations for equality tests on their behalf when offline. Importantly, the proxy token used in our scheme does not include any portion of the user’s private key, providing enhanced protection compared to traditional PKEET schemes in which the user token is often part of the user’s private key. We construct a concrete CLE-MET-PA scheme and prove that it achieves CPA security and attains CCA security through an FO transformation.
The replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts.
Accountable identity-based encryption (A-IBE) was proposed to relieve the key escrow problem caused by the fully trustworthy private-key generator (PKG) in the IBE system, where the true generator of private keys or decoder boxes can be traced back to the PKG or related users. Retrievable A-IBE (RA-IBE) enhances the security of A-IBE by providing retrievability to the master secret key of the PKG when more than one private key of the same user are released. RA-IBE strengthens the deterrent effect of A-IBE against the PKG since disclosure of the master secret key could lead to the breakdown of the entire IBE system. However, current RA-IBE schemes only provide retrievability in a white-box model, which limits the ability to support traceability and retrievability on well-formed private keys only. This overlooks the fact that a malicious PKG can easily conceal a private key within a decoder box, making the inserted private key inaccessible. To overcome this limitation, we propose a full black-box RA-IBE scheme, where traceability and retrievability of decoder boxes are provided while the malicious PKG is allowed to access the decryption oracle in the security model simultaneously. We first give the formal definition and security models of full black-box RA-IBE and then present a concrete construction. In our construction, a user interacts with the PKG to obtain its private key and an additional commitment tuple with which the user can retrieve the master secret key of the PKG using a related decoder box generated by the PKG. Finally, we show that the proposed full black-box RA-IBE scheme is secure in the random oracle model.
Ethereum leverages ECDSA as the digital signature scheme to validate transactions. From the provable security standpoint, ECDSA built on an 80-bit security Elliptic Curve group can achieve at most 50-bit concrete security, rather than 80-bit security, due to its reduction loss for 230 signature queries in security analysis. The state-of-the-art ECDSA scheme comes with no de facto formal security guarantee. Although there have been many signatures with higher concrete security, their structures are quite different from ECDSA and a total replacement of the signature field in Ethereum will incur high deployment cost. In this work, we present EthereumX without compromising the signature structure in Ethereum while achieves better security. The security gain is built on top of a new technique named randomness pre-processing module (RPM), which can securely pre-generate and verify randomness with the help of Ethereum. Calling RPM allows to pre-select randomness, which will be used for the subsequent signature, and to verify the randomness, assuring that it is previously generated. We give an instantiation with formal security guarantee and prove that it can be improved to 80-bit concrete security under the same discrete logarithm assumption as ECDSA. From this instantiated scheme, we implement EthereumX via a deployment into a locally simulated network. Experiment results show that EthereumX costs 5 seconds for a block generation which is equal to Ethereum, and generates/verifies at least 17017/10623 transactions per second that is practical enough in application, even if they are slightly slower than Ethereumwhich generates/verifies at least 17908/11257 transactions per second. We also mention that RMP can be applied to other DL-based signatures for the security improvement.
Public-key encryption with equality test (PKEET) provides cloud servers with an effective way to check the equality of outsourced encrypted data without decryption. This enables PKEET to attract much attention and be widely researched in cloud computing. However, we claim that the existing PKEET schemes suffer from an inherited problem, called message-consistency unverifiability of testers (MCUT). Applying the MCUT problem, outsourcers can fool cloud servers into outputting incorrect testing results of encrypted data, which negates the practicability of PKEET in cloud computing. We investigate the PKEET literature and find the main reason for the MCUT problem is the independence between the messages inserted in the decryption and testing modules in their ciphertexts. To bridge the technical gap between PKEET and its practical applications, we present a new notion, called PKE with tester verifiable equality test (PKE-TVET), which solves the MCUT problem by allowing testers to verify the message consistency in two modules. We then instantiate the PKE-TVET and give a specific construction in the standard model. In our PKE-TVET scheme, the testing module is integrated into the decryption module so that there is only one message inserted in the ciphertext for both decryption and testing. This special setting lets our scheme directly get rid of the MCUT problem. For better applications in actual scenarios, we further extend the scheme to support authorization and tester designation. Finally, we analyze the tradeoff of parameter sizes and computation costs for the security against MCUT attacks in our PKE-TVET scheme.
In a traditional health system, it merely depends on doctors’ initiative reports to discover infectious diseases, which causes late responses from the Center for Disease Control (CDC) and therefore may result in snowballed loss of lives and economy. Sometimes, the disease has spread when doctors realize it is infectious, and the CDC has to invest more human and material resources to control it. In this article, we propose a new secure infectious diseases detection system with the help of the IoT-based e-health platform. In our system model, the hospitals collect patients’ electronic health records (EHRs) and outsource the encrypted EHRs to the contracted cloud. The CDC can regularly send a test query to the cloud server to check whether there are patients who have similar symptoms or some increasing signs, which are regarded as signs of infectious diseases. With this system, the CDC can find the small signs of infectious diseases so that it can make appropriate and timely measures to save more lives. To enable the cloud server to perform the required test, we propose a new cryptographic notion, called public-key encryption with DFET (PKE-DFET), with which we can check whether the underlying messages of two ciphertexts are equal or not after ignoring the bits on designated positions without decryption. The cloud server can utilize the PKE-DFET to flexibly count the number of patients with similar symptoms following the CDC’s instructions. We first instantiate the PKE-DFET into a concrete construction, where anyone can be a tester to perform the DFET on ciphertexts. Finally, we extend our PKE-DFET construction to enable it to be flexible in different actual application scenarios.
Abstract Confronted with severe challenges from quantum computers on public-key cryptography based on traditional number theory, post-quantum cryptography (PQC) has received a substantial amount of attentions. However, suffering from time-consuming polynomial operations, most post-quantum schemes cannot be really applied in practice, especially in high-concurrency scenarios. In this paper, we focus on the post-quantum signature algorithm, DILITHIUM, and present an optimized and highly parallel implementation on Graphics Processing Units (GPU). We give two optimized versions, named single mode and batch mode. In the scheme of single mode, we show efficient implementations of number theoretic transformations (NTT) and other polynomial operations adapted to the scheme. In the batch mode, we improve the reject sampling algorithm for the simultaneous processing of multiple sets of data. Finally, we implement our schemes on GPUs with different architectures, such as Pascal, Volta, and Turing, which shows that the speedup ratio of our schemes increases with the increasing of processed data number. The speedup is up to 11.18× for 15360 groups of data in our experimental environment. In the single mode, We can achieve a speedup of more than 4× for complex operations, such as NTT and its inverse. Other simpler operations such as reduce, caddq and decompose can also achieve an acceleration of 2× ~ 4×. In comparison with the original DILITHIUM scheme testing in the high-performance CPU 6133, our scheme finally has a 1.22× speedup even after taking the communication overhead between CPU and GPU into consideration.
目的 探讨MRI在胎儿肠梗阻诊断中的价值.方法 回顾性分析28例胎儿肠梗阻的产前MRI表现,其中26例产前超声提示胎儿肠管扩张,2例未见明显异常.结果 十二指肠及空肠狭窄共7例,梗阻近端肠管T1 WI呈低信号,远端肠管基本正常.空回肠闭锁8例,近端肠管T1 WI呈高信号6例,低信号2例,结直肠明显细小7例,正常1例.肛门闭锁2例,直肠末端位于膀胱颈上方.肠旋转不良4例,十二指肠扩张呈螺旋状3例.环状胰腺4例,十二指肠降部周围见带状影环绕.肠扭转2例,肠套叠1例,分别见"漩涡征"及"同心圆征",近端肠管T1 WI及扩散加权成像(DWI)序列均呈高信号.结论 胎儿肠梗阻的MRI检查可根据梗阻端的形态及近端肠管信号特征,准确地判定梗阻的水平及原因,并可评估远端肠管的发育,对产前咨询和产后治疗有重要的指导意义.
Public key encryption with equality test (PKEET) can check whether two ciphertexts are encrypted from the same message or not without decryption. This attribute enables PKEET to be increasingly utilized in cloud storage, where users store their encrypted data on the cloud. In traditional PKEET, the tester is authorized by the data receiver to perform equality test on its ciphertexts. However, the tester can only test one ciphertext or all ciphertexts of one receiver with one authorization. It means that the receiver cannot adaptively authorize the test right of any number of ciphertexts to the tester. A trivial solution is authorizing one ciphertext each time and repeating multiple times. The corresponding size of trapdoor in this method is linear with the number of authorized ciphertexts. This will incur storage burden for the tester. To solve the aforementioned problem, we propose the concept of PKEET supporting partial authentication (PKEET-PA). We then instantiate the concept to a lightweight PKEET-PA, which achieves constant-size trapdoor. Besides, we prove the security of our PKEET-PA scheme against two types of adversaries. Compared with other PKEET schemes that can be used in trivial solution, our PKEET-PA is more efficient in receivers’ computation and has lower trapdoor size.
Tightly secure signature plays a significant role in the research of cryptography and has been studied extensively in the literature. In this paper, we present a generic construction for tightly-secure signatures from the discrete log (DL) assumption in the existential-unforgeability against key only attacks (EUF-KOA) security model, where the adversary is allowed to obtain only the public key, but not any sample signature. Moreover, the generic construction can also be extended into the multi-user setting with corruptions (MU-C) model. Roughly speaking, given any signature scheme, we can efficiently convert it into a signature scheme that features tight security under the DL assumption in the MU-EUF-KOA-C security model with random oracles. Our transformation shows it is easy to construct a DL-equivalent signature in the EUF-KOA security model, although many known DL-based signatures are not equivalent to DL. If the given signature scheme is key-re-randomizable, the transformed scheme is also key-re-randomizable. Hence, our result provides a supplement to Bader et al.'s work (EUROCRYPT 2016).