[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-203829-105":3,"detail-sidebar-cat-0-en-105":81,"doc-detail-203829-en":130},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":74,"head_meta":76,"extra_data":78,"updated_unix":80},105,"en","designated-ciphertext-searchable-encryption-insider-keyword-guessing-attack-prevention-generic-dcse-scheme-and-lattice-based-construction","Designated-Ciphertext Searchable Encryption - Insider Keyword Guessing Attack Prevention - Generic DCSE Scheme and Lattice-Based Construction","","Designated-ciphertext searchable encryption (DCSE) addresses insider keyword guessing attacks in public-key encryption with keyword search (PEKS). After a malicious insider receives a trapdoor, it can encrypt candidate keywords with the user’s public key and test correspondence, revealing sensitive information. DCSE assigns each trapdoor to a specific ciphertext, blocking IKGA. The work proposes a generic DCSE using identity-based encryption and key encapsulation, proves its security, and provides a lattice-based instantiation resistant to quantum attacks based on NTRU and ring-learning with errors.",{"@graph":14,"@context":73},[15,34,56],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/document/","Document",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/document/technology/","Technology",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/document/designated-ciphertext-searchable-encryption-insider-keyword-guessing-attack-prevention-generic-dcse-scheme-and-lattice-based-construction/203829/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/designated-ciphertext-searchable-encryption-insider-keyword-guessing-attack-prevention-generic-dcse-scheme-and-lattice-based-construction/203829.png","ImageObject",300,407,{"name":42,"@type":43},"Angel","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-10-10","2026-09-04",true,{"@type":52,"interactionType":53,"userInteractionCount":55},"InteractionCounter",{"@type":54},"ViewAction",9,{"@type":57,"mainEntity":58},"FAQPage",[59,65,69],{"name":60,"@type":61,"acceptedAnswer":62},"What problem does PEKS face in cloud and IoT settings?","Question",{"text":63,"@type":64},"PEKS enables searchable encryption for encrypted data, but many schemes assume insiders are trustworthy and do not defend against attacks where insiders guess keywords from trapdoors.","Answer",{"name":66,"@type":61,"acceptedAnswer":67},"How does an insider keyword guessing attack (IKGA) work?",{"text":68,"@type":64},"After receiving a trapdoor, a malicious insider encrypts candidate keywords using the authorized receiver’s public key and tests whether the trapdoor matches the selected keyword.",{"name":70,"@type":61,"acceptedAnswer":71},"What does DCSE change to prevent IKGA?",{"text":72,"@type":64},"DCSE designates each trapdoor for a specific ciphertext, so malicious insiders cannot use the same trapdoor to test arbitrary guessed keywords.","https://schema.org",{"og:url":32,"og:type":75,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":77,"canonical":32},"index,follow",{"doc_id":79,"site_id":7},203829,1790388905,{"code":4,"msg":82,"data":83},"success",[84,88,92,96,101,105,110,115,119,122,126],{"id":22,"doc_module":4,"doc_module_name":25,"category_name":85,"show_sort_weight":86,"slug":87},"Story & Novel",90,"story-novel",{"id":26,"doc_module":4,"doc_module_name":25,"category_name":89,"show_sort_weight":90,"slug":91},"Literature",80,"literature",{"id":33,"doc_module":4,"doc_module_name":25,"category_name":93,"show_sort_weight":94,"slug":95},"Exam",70,"exam",{"id":97,"doc_module":4,"doc_module_name":25,"category_name":98,"show_sort_weight":99,"slug":100},5,"Comic",60,"comic",{"id":102,"doc_module":4,"doc_module_name":25,"category_name":29,"show_sort_weight":103,"slug":104},6,50,"technology",{"id":106,"doc_module":4,"doc_module_name":25,"category_name":107,"show_sort_weight":108,"slug":109},7,"Healthcare",40,"healthcare",{"id":111,"doc_module":4,"doc_module_name":25,"category_name":112,"show_sort_weight":113,"slug":114},8,"Research & Report",30,"research-report",{"id":55,"doc_module":4,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":25,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":25,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":25,"category_name":128,"show_sort_weight":97,"slug":129},19,"General","general",{"code":4,"msg":82,"data":131},{"doc_id":79,"user_id":132,"nickname":42,"user_avatar":133,"doc_module":4,"category_id":102,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":55,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":139,"language":140,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":12,"update_tm":144,"read_time":145},687207412472,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","Designated-ciphertext Searchable Encryption  \nZi-Yuan Liu 1 , Yi-Fan Tseng 1 ? , Raylin Tso 1 , and Masahiro Mambo2  \n1 Department of Computer Science, National Chengchi University, Taipei 11605, Taiwan  \nfzyliu, yftseng, [raylin](rayling@cs.nccu.edu.tw)[g](rayling@cs.nccu.edu.tw)[@cs.nccu.edu.tw](rayling@cs.nccu.edu.tw)  \n2 Institute of Science and Engineering, Kanazawa University, Kakuma-machi, Kanazawa 920-1192, Japan  \n[mambo@ec.t.kanazawa-u.ac.jp](mambo@ec.t.kanazawa-u.ac.jp)  \nAbstract. Public-key encryption with keyword search (PEKS), proposed by Boneh et al. , allows users to search encrypted keywords without losing data privacy. Although extensive studies have been conducted on this topic, only a few have focused on insider keyword guessing attacks (IKGA) that can reveal a user's sensitive information. In particular, after receiving a trapdoor used to search ciphertext from a user, a malicious insider (e.g., a server) can randomly encrypt possible keywords using a user's public key, and then test whether the trapdoor corresponds to the selected keyword. This paper introduces a new concept called designatedciphertext searchable encryption (DCSE), which provides the same desired functionality as a PEKS scheme and prevents IKGA. Each trapdoor in DCSE is designated to a speci􀀌c ciphertext, and thus malicious insiders cannot perform IKGA. We further propose a generic DCSE scheme that employs identity-based encryption and a key encapsulation mechanism. We provide formal proofs to demonstrate that the generic construction satis􀀌es the security requirements. Moreover, we provide a lattice-based instantiation whose security is based on NTRU and ring-learning with errors assumptions; the proposed scheme is thus considered to be resistant to the quantum-computing attacks.  \nKeywords: Quantum-resistant 􀀁 Searchable Encryption 􀀁 Insider Keyword Guessing Attack 􀀁 Designatedciphertext 􀀁 Lattices  \n1 Introduction  \nWith the development of the 5G and Internet of Things (IoT), the importance of cloud storage is increasing. However, because the cloud providers cannot be easily trusted, to avoid data leakage or abuse, data owners need to ensure the privacy of sensitive data. A straightforward method is data encryption before upload to cloud servers. However, encrypted data loses its processing 􀀍exibility and cannot be used for useful operations, such as sorting or searching. Speci􀀌cally, search functionality is important for cloud storage. If a data owner wants to search for some speci􀀌c 􀀌les among large encrypted data sets, it becomes necessary to download and decrypt all the data to search, which is impractical and resource-consuming. To resolve this issue, Song et al. [45] proposed the 􀀌rst searchable encryption (SE) that allows the ciphertext to be searched using the corresponding trapdoor. However, because their construction is based on a symmetric key primitive, only the owner of a particular secret key can generate any corresponding ciphertext and trapdoor. Hence, as with a symmetric cryptosystem, their work faces the key distribution problem when it is deployed in public cloud environments.  \n1.1 Public-key Encryption with Keyword Search  \nTo circumvent the issue of the symmetric searchable encryption and allow multiple data owners to easily generate di􀀋erent ciphertexts for a single data receiver, Boneh et al. [10] proposed the 􀀌rst public-key encryption with keyword search (PEKS) . The scheme, unlike Song et al.'s work [45], is built on a public-key cryptosystem. The PEKS scheme has three entities: data owner (Alice), data receiver (Bob), and cloud server. Consider the following scenario: Alice wants to store 􀀌les that can be accessed and searched by Bob without any leakage of information to the cloud server. Therefore, in addition to encrypting 􀀌les using Bob's public key pk, she also encrypts the related keywords of the 􀀌les using a PEKS algorithm that allows ciphertexts to be searched, e.g. , Enc (pk; 􀀌le)kPEKS(pk; \\pkc\")k 􀀁","cbCaifBfpFTf5lxl","https://ap.wps.com/l/cbCaifBfpFTf5lxl","pdf",1364263,18,"English","# Abstract\n# Introduction\n## Public-key Encryption with Keyword Search\n## Motivation","[{\"question\":\"What problem does PEKS face in cloud and IoT settings?\",\"answer\":\"PEKS enables searchable encryption for encrypted data, but many schemes assume insiders are trustworthy and do not defend against attacks where insiders guess keywords from trapdoors.\"},{\"question\":\"How does an insider keyword guessing attack (IKGA) work?\",\"answer\":\"After receiving a trapdoor, a malicious insider encrypts candidate keywords using the authorized receiver’s public key and tests whether the trapdoor matches the selected keyword.\"},{\"question\":\"What does DCSE change to prevent IKGA?\",\"answer\":\"DCSE designates each trapdoor for a specific ciphertext, so malicious insiders cannot use the same trapdoor to test arbitrary guessed keywords.\"}]","Designated-Ciphertext Searchable Encryption - Insider Keyword Guessing Attack Prevention - Generic DCSE Scheme and Lattice-Based Construction | PDF",1788564182,45]