Abstract
Dynamic searchable symmetric encryption (DSSE) schemes empower data owners to outsource their encrypted data to clouds while retaining the ability to update or search on it. Despite a lot of efforts devoted in recent years, there are still several challenges that have not been well addressed. First, the confidentiality of data might be compromised if forward privacy and backward privacy cannot be ensured. Second, only the traditional single keyword-file search has attracted tremendous attention, while other popular queries like Boolean queries and range queries are not fully investigated. Lastly, how to solve these problems on untrusted servers that may deviate from pre-defined protocols is also challenging. In this article, aiming to tackle the above problems, we propose a novel DSSE scheme named HeX based on Trusted Execution Environment (TEE) that supports rich queries on untrusted servers while guaranteeing forward and backward privacy. We achieve strong forward and backward security by designing a deferred obfuscating read-write technique atop the bitmap index. We further extend the basic scheme to realize Boolean queries and range queries by reducing them to basic keyword queries. Strict theoretical analysis is conducted to prove the security of HeX, and extensive evaluations illustrate its efficiency and practicality.
| Original language | English |
|---|---|
| Pages (from-to) | 3751-3765 |
| Number of pages | 15 |
| Journal | IEEE Transactions on Dependable and Secure Computing |
| Volume | 22 |
| Issue number | 4 |
| DOIs | |
| Publication status | Published - Jul 2025 |
Keywords
- Dynamic searchable symmetric encryption
- backward privacy
- forward privacy
- rich queries
- trusted execution environment
ASJC Scopus subject areas
- General Computer Science
- Electrical and Electronic Engineering