已有的可搜索加密方案(PEKS),都是实现对关键词信息的保护。一个真正安全的可搜索加密方案,在保证搜索能力的前提下,不仅要实现对关键词信息的保护,也要实现对消息查询方信息的保护。基于此,提出了具有匿名性的基于身份可搜索方案(ANO-IBEKS)的定义和构造算法。该方案可以很好的解决大量数据交给第三方服务器存储(比如网络存储)的关键词密文查询问题,可以有效的保护查询关键词和查询者身份等敏感信息,无法追踪究竞是哪个用户查询了什么信息,并且给出了方案在随机预言机模型下语义安全性的证明。
For the existing schemes of public key encryption with keyword search (shorthand for PEKS), the purpose is to protect the information of keyword except for the searchable function. In fact, a genuine safe PEKS should provide not only the security of keywords but also the security of users. So that, on the basis of existing anonymous hierarchical identity-based encryption scheme (ANO-IBE), the scheme of anonymous identity based public key encryption with keyword search (ANO-IBEKS) is firstly proposed. The program can provide the function of protecting both the information of keyword and identity of the users under the circumstance of a lot of data to the third party server storage (such as network storage). In this scheme, severs cannot track exactly which user queries relevant information. The semantic security proof of ANO-IBEKS is gaven in the random oracle model.