[論文レビュー] Towards Blockchain-enabled Searchable Encryption
本稿では、元の方式のプライバシーを保ちつつ検索操作のフェアネスを達成する、ブロックチェーンを活用した対称検索可能暗号のフレームワークを2つ提案する。ブロックチェーンは、トラップドアやインデックスを露呈しないように、署名、暗号化された結果、パブリックメタデータのみを格納するために使用することで、検証可能な正しさとサーバーへの報酬を確保しつつ、元の方式を超えるプライバシー漏洩を防ぐ。
Distributed Leger Technologies (DLTs), most notably Blockchain technologies, bring decentralised platforms that eliminate a single trusted third party and avoid the notorious single point of failure vulnerability. Since Nakamoto's Bitcoin cryptocurrency system, an enormous number of decentralised applications have been proposed on top of these technologies, aiming at more transparency and trustworthiness than their traditional counterparts. These applications spread over a lot of areas, e.g. financial services, healthcare, transportation, supply chain management, and cloud computing. While Blockchain brings transparency and decentralised trust intuitively due to the consensus of a (very large) group of nodes (or, miners), it introduces very subtle implications for other desirable properties such as privacy. In this work, we demonstrate these subtle implications for Blockchain-based searchable encryption solutions, which are one specific use case of cloud computing services. These solutions rely on Blockchain to achieve both the standard privacy property and the new fairness property, which requires that search operations are carried out faithfully and are rewarded accordingly. We show that directly replacing the server in an existing searchable encryption solution with a Blockchain will cause undesirable operational cost, privacy loss, and security vulnerabilities. The analysis results indicate that a dedicated server is still needed to achieve the desired privacy guarantee. To this end, we propose two frameworks which can be instantiated based on most existing searchable encryption schemes. Through analysing these two frameworks, we affirmatively show that a carefully engineered Blockchain-based solution can achieve the desired fairness property while preserving the privacy guarantee of the original searchable encryption scheme simultaneously.
研究の動機と目的
- クラウドベースの検索可能暗号において、サーバーが検索を忠実に実行しないというフェアネスや信頼の欠如に対処する。
- 検索可能暗号システムにおいて、クラウドサーバーを単純にブロックチェーンに置き換えるリスクを分析する。
- 既存の対称検索可能暗号方式のプライバシー保証を維持するように、ブロックチェーンを統合したフレームワークを設計する。
- 検索操作が検証可能であり、誠実なサーバーが公平に報酬を得られることを保証する。
- ブロックチェーンを検索可能暗号に効果的に活用でき、新たなプライバシーまたはセキュリティの脆弱性をもたらさないことを実証する。
提案手法
- 各キーワードに対してHMACを用いて仮想識別子を生成する変更済みセットアップ段階を導入し、ファイル識別子を検索結果に束縛する。
- ブロックチェーンを、暗号化された検索結果、署名、パブリックキー、預り金といったパブリック情報のみに使用する。
- サーバーが正しい結果を返さない場合に処罰される紛争解決メカニズムを採用し、HMACベースの整合性チェックにより検証する。
- 標準的な暗号プリミティブに依存する:EU-CMA安全な署名とIND-CPA安全な暗号化であり、単一の整合性仮定のもとで機密性が保証される。
- クライアントがHMAC保護された仮想識別子を用いて正しさを検証するリトリーブおよび検証段階を設計する。
- ブロックチェーンに露出するのは、署名、暗号化された結果、パブリックキーのみに限定され、プライバシーが保持される。
実験結果
リサーチクエスチョン
- RQ1検索可能暗号において、元の方式のプライバシーを損なわずに、フェアネスを強制するためにブロックチェーンを使用できるか?
- RQ2検索可能暗号システムにおいて、サーバーを直接ブロックチェーンに置き換えると、プライバシーおよびセキュリティにどのような影響があるか?
- RQ3オーバーヘッドを最小限に抑えるとともに、検証可能な検索操作を可能にするために、どのようにブロックチェーンを統合できるか?
- RQ4ブロックチェーン強化型検索可能暗号において、フェアネスと機密性の両方を保証するために必要な暗号メカニズムは何か?
- RQ5専用サーバーとブロックチェーンを併用するハイブリッドモデルは、完全に分散化された代替案よりも、より優れたプライバシーとフェアネスを達成できるか?
主な発見
- 検索可能暗号において、サーバーを直接ブロックチェーンに置き換えると、運用コストの増加、プライバシー漏洩、セキュリティ脆弱性が生じる。
- 提案されたフレームワークは、ブロックチェーンにトラップドアや暗号化インデックスではなく、パブリックメタデータのみを格納するため、元の方式のプライバシー保証を維持する。
- ブロックチェーンは、署名、暗号化された結果、パブリックキーのみを格納するために使用され、サーバーに追加の情報が漏洩しない。
- フェアネスは、不正なサーバーが処罰され、誠実なサーバーが検証可能な結果に基づいて報酬を得る紛争解決メカニズムによって達成される。
- 通常の運用においてブロックチェーンの影響は最小限であり、1回の検索あたり数件のパブリックレコードしか書き込まれない。
- IND-CPA機密性とEU-CMA改ざん不能性が維持され、標準仮定のもとでセキュリティが保証される。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。