FBR-PAEKS: revocable public-key authenticated keyword search with forward privacy for dynamic cloud environments
Abstract
This study presents Forward-private and Binary-tree-Revocable PAEKS (FBR-PAEKS), a public-key authenticated encryption with keyword search scheme for secure multi-user cloud environments that integrates forward privacy and cryptographic revocation in a single construction. The proposed scheme supports expressive keyword search policies represented by linear secret-sharing schemes (LSSS), enabling flexible AND, OR, and threshold-based queries over encrypted indexes. FBR-PAEKS integrates a binary-tree-based revocation mechanism using the complete-subtree algorithm KUNode , an epoch-bound one-way state evolution chain for forward privacy, and a deletion-tag filter for logical document deletion. To resist insider keyword-guessing attacks by the cloud server, the construction introduces a sender–receiver shared element derived from the Diffie–Hellman value of their secret keys. Furthermore, the receiver's epoch secret is embedded into the trapdoor exponent to prevent current-state compromise from exposing past search information. We formalized the security of the scheme through ciphertext indistinguishability, resistance to insider keyword guessing, revocation unforgeability, forward privacy under state compromise, and trapdoor integrity. The security reductions are established under the CDH, mDLIN, PRF, one-wayness, and signature unforgeability assumptions in the random oracle model. Theoretical and practical evaluations show that FBR-PAEKS achieves strong security and expressive search functionality with competitive performance compared with existing PAEKS schemes.