为了提高查询验证技术的安全性和计算速度,分析了数字签名链查询验证技术的结构特征,指出其具有数据库构建成本高、验证速度慢和安全性低等不足.将指定验证人签名的思想引人到外包数据库查询验证技术中,并根据外包数据库的安全需求设计了1个指定验证人签名方案,然后结合该签名方案提出一种安全、高效的可保护隐私数据的查询验证技术.该技术在查询验证过程中隐藏了数据拥有者的签名,能防止合谋攻击和伪冒攻击,可实施复杂的内容访问控制策略、保护隐私数据.理论分析和实验数据表明,该查询验证技术的数据库创建成本低、存储开销小、验证速度快、安全性高.
In order to improve the security and calculation speed of the query verification techniques, structural traits of the signature chain query verification scheme are analyzed, and that it has drawbacks of tremendous database construction cost, slow authentication and insufficient security is pointed out. Firstly, the ideas of designated verifier signature technology into query answer assurance techniques of outsourced databases are introduced, and a designated verifier signature scheme according to the security requirements of query authentication techniques is designed. Then we propose a secure, super-efficient query authentication scheme using the signature scheme is proposed. The proposed authentication scheme does conceal the owner's signature during the query verification process, and can prevent collusion attacks. Moreover, the scheme can enforce advanced content access control policies and preserve data privacy and sensitive information. Both theoretical analysis and experimental results demonstrate that the approach is time and space efficient.