对指定测试者的基于身份可搜索加密(dIBEKS)方案进行了研究。指出Tseng等人所提dIBEKS方案并不是完全定义在基于身份密码系统架构上,而且方案不能满足dIBEKS密文不可区分性。首次提出了基于身份密码系统下的指定测试者可搜索加密方案的定义和安全需求,并设计了一个高效的dIBEKS新方案。证明了dIBEKS密文不可区分性是抵御离线关键字猜测攻击的充分条件,并证明了新方案在随机预言模型下满足适应性选择消息攻击的dIBEKS密文不可区分性、陷门不可区分性,从而可以有效抵御离线关键字猜测攻击。
Identity-based searchable encryption scheme with a designated tester(dlBEKS scheme) is studied. The dlBEKS scheme proposed by Tseng et al is analyzed and it shows the scheme is not totally based on identity-based cryptosystem, and the scheme can not satisfy the dlBEKS ciphertext indistinguishability. The definition and security requirements of dlBEKS scheme are firstly presented, and an efficient dlBEKS scheme construction is proposed. After proving the dlBEKS ciphertext indistinguishability is the sufficient condition for thwarting offline keyword guessing at- tack, the new dlBEKS scheme can satisfy dlBEKS ciphertext indistinguishability, trapdoor indistinguishability and offline keyword guessing resistance under the adaptive chosen message attack in the random oracle model.