针对移动终端息票定向投放服务中的隐私安全问题,提出一种支持加密搜索的定向息票安全投放框架。该框架根据息票定向投放过程中不同阶段的安全需求,通过使用多密钥可搜索加密技术实现移动终端用户只需要提交单个加密请求,就能在息票平台中对来自不同商家的加密息票进行安全高效的搜索,降低了系统的通信开销;同时结合局部敏感哈希技术和口令认证密钥交换协议,保证只有行为数据满足商家息票投放策略的移动用户才能获得息票,保护了移动终端用户的行为数据隐私和商家的息票投放策略。理论分析证明了该框架的安全性。实验结果表明,移动用户使用该框架获取10个商家的息票时所需计算时间为57.8ms,带宽为2.9KiB,能耗为8.7J。所提框架在息票定向投放服务的安全性和性能方面取得了很好的平衡,适合在移动终端上使用,对设计安全、实用的定向投放应用具有一定的理论和实际意义。
A framework of secure delivery service of targeted coupons with encrypted search is proposed to solve privacy issues of users and vendors in delivery service of mobile targeted coupons. The proposed framework adopts a newly developed cryptographic primitive, called multi-key searchable encryption, which ensures that a user only needs to submit a single encrypted request to the coupon site so as to conduct secure and effective search over encrypted coupons from different vendors. Meanwhile, the framework ensures that eligible users can obtain targeted coupons without leaking their behavioral data while non-eligible users learn nothing beyond their non-eligibility status by combining locality-sensitive hashing with password authenticated key exchange. Theoretical analysis proves the security of the proposed framework. Extensive experiments show that when a mobile user obtains coupons from 10 different vendors, the computation cost of the proposed framework is 57.8 ms, bandwidth cost 2.9 KiB, and energy cost 8.7 J. The proposed framework provides a well-balanced tradeoff between security and efficiency, and has certain theoretical and practical significance for the design of secure and practical targeted delivery systems.