TY - JOUR
T1 - Toward Reliable and Secure Cloud Services With Fault-Tolerant Searchable Encryption
AU - Zuo, Cong
AU - Wang, Bingjing
AU - Liu, Jianghua
AU - Cui, Shujie
AU - Shao, Jun
AU - Wang, Huaxiong
AU - Zhu, Liehuang
AU - Russello, Giovanni
N1 - Publisher Copyright:
© 2008-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Dynamic Searchable Symmetric Encryption (DSSE) plays a crucial role in secure cloud-based database systems, as it enables efficient keyword search and dynamic updates over encrypted data. However, practical deployment of DSSE schemes faces two significant challenges. First, clients may inadvertently perform faulty updates—such as re-adding an existing keyword-identifier pair or attempting to delete a non-existent one—which can compromise the correctness of subsequent search results. Second, even with correctly issued updates, malicious servers may return incorrect or incomplete search results, undermining data integrity. To address these challenges, we propose FVDSSE, the first fault-tolerant DSSE scheme that tolerates client-side operational faults and provides result verifiability against malicious servers. Moreover, it simultaneously ensures strong privacy by guaranteeing forward and backward privacy—two essential properties for any practical DSSE. To further optimize performance, we present FVDSSE-C, an enhanced variant that leverages caching techniques. Experimental evaluations on a real-world dataset show that FVDSSE-C achieves up to 130× improvement in search efficiency and 3× reduction in communication overhead compared to the state-of-the-art scheme (YCR22-C).
AB - Dynamic Searchable Symmetric Encryption (DSSE) plays a crucial role in secure cloud-based database systems, as it enables efficient keyword search and dynamic updates over encrypted data. However, practical deployment of DSSE schemes faces two significant challenges. First, clients may inadvertently perform faulty updates—such as re-adding an existing keyword-identifier pair or attempting to delete a non-existent one—which can compromise the correctness of subsequent search results. Second, even with correctly issued updates, malicious servers may return incorrect or incomplete search results, undermining data integrity. To address these challenges, we propose FVDSSE, the first fault-tolerant DSSE scheme that tolerates client-side operational faults and provides result verifiability against malicious servers. Moreover, it simultaneously ensures strong privacy by guaranteeing forward and backward privacy—two essential properties for any practical DSSE. To further optimize performance, we present FVDSSE-C, an enhanced variant that leverages caching techniques. Experimental evaluations on a real-world dataset show that FVDSSE-C achieves up to 130× improvement in search efficiency and 3× reduction in communication overhead compared to the state-of-the-art scheme (YCR22-C).
KW - Backward privacy
KW - dynamic searchable symmetric encryption
KW - fault-tolerance
KW - forward privacy
KW - verifiability
UR - https://www.scopus.com/pages/publications/105040528604
U2 - 10.1109/TSC.2026.3698022
DO - 10.1109/TSC.2026.3698022
M3 - Article
AN - SCOPUS:105040528604
SN - 1939-1374
JO - IEEE Transactions on Services Computing
JF - IEEE Transactions on Services Computing
ER -