透過您的圖書館登入
IP:3.145.33.219
  • 期刊
  • OpenAccess

Security of a UUP Web Search Protocol with Privacy Preserving

具隱私保護的UUP網頁搜尋引擎協定之安全探討

摘要


Generally, a search engine will keep a record of a user about the websites he ever went and the past searches he had submitted to improve its performance. Similar to a spy tracking and tracing the footpath, a search engine will inevitably violate user's privacy as the record will reveal the user's personal information or the institution he works for. To protect user's privacy, Castellà-Roca et al. proposed a protocol called Useless User Profile (UUP), in which it provided a distorted user profile for a web search engine such that the web search engine cannot generate a real profile of a certain individual. One of the significant advantages lies on that their protocol requires no change in the server side and the server is not required to collaborate with the user. However, to claim security guarantee of new image cryptosystems is meaningful only when the cryptanalysis is taken into consideration. The UUP protocol was claimed to be secure; however, a potential collusion attack is pointed out. In order to benefit the advantages and contribution of Castellà-Roca et al.'s scheme, this paper redesigns a security-improved version by simple modification to remove the possible security concern. Precisely, to correct the shortcoming, the authors suggest the user's query be encrypted firstly by means of the server's public key and then each answer also be encrypted by a session key.

並列摘要


一般而言,網路搜尋引擎會紀錄使用的使用動態名為改進效能,然而這樣也違反使用者的個人隱私。因此,Castellà-Roca等提出UUP協定。該協定下,使用者不再需要提供完整的使用資訊,伺服器端得到的並不是某位使用者完整的使用資訊。值得注意的,伺服器端不用修改且不用與使用者配合修改。然而,基於宣稱安全的一個新的密碼技術必須經過安全分析後才有意義,本研究發現該協定有共謀攻擊的可能,當群組中的欺騙者人數高達n-1時,最後一位使用將可能受到共謀欺騙。為了維持Castellà-Roca等提出UUP協定的優點,本文對其進行小而簡單的修改以補強其安全性。主要改進的設計在於使用者先以伺服器的公開金鑰對查詢內容加密,而伺服器回應的內容則以一把會議金鑰加密後傳回。

延伸閱讀