An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls
DOI:
https://doi.org/10.26740/vubeta.v3i3.52993Keywords:
Certificateless Public Key , Encryption, Cryptographic Reverse , Firewalls, IND-CCA2 Security, Bilinear Pairings, Exfiltration ResistanceAbstract
Secure communication in Internet of Things (IoT), cloud computing, and peer-to-peer environments requires efficient cryptographic schemes resilient to advanced threats. Public Key Infrastructure (PKI) incurs certificate management overhead, while Identity-Based Encryption (IBE) introduces key escrow. Certificateless Public Key Encryption (CL-PKE) addresses these limitations, but existing constructions integrating Cryptographic Reverse Firewalls (CRFs) remain computationally expensive and lack IND-CCA2 security guarantees. This study develops an optimized CL-PKE-CRF scheme using a single-element public key, sender-side precomputation of pairing operations, and independent per-user randomization through a Key Derivation Function (KDF) at the Key Generation Center (KGC). The scheme was implemented using Charm-Crypto and evaluated over 1,000 iterations at 128-, 192-, and 256-bit security levels. Compared with the baseline, it reduced computational overhead by approximately 25% and communication costs by 33%, while subsequent encryption latency decreased by 76.6% for repeated operations. Simulated evaluations reported adversarial advantage below 0.004, 100% decryption correctness, and no observed information leakage across the tested compromise scenarios. A formal IND-CCA2 security reduction under the Computational Bilinear Diffie-Hellman (CBDH) assumption in the random oracle model is also presented. These findings demonstrate improved efficiency and resistance to exfiltration attacks, supporting secure communication in resource-constrained environments.
References
[1] M. Idris Abubakar, A. Ore-Ofe, A. Umar, I. Ibrahim, L. A. Olugbenga, and A. Abdulbasit Abiola, “Design of an Enterprise Network Terminal Security Solution,” Vokasi Unesa Bulletin of Engineering, Technology and Applied Science, vol. 2, no. 3, pp. 412–427, Aug. 2025. https://doi.org/10.26740/vubeta.v2i3.39105
[2] C. Abou Haidar, A. Passelègue, and D. Stehlé, “Efficient Updatable Public-Key Encryption from Lattices,” in Advances in Cryptology – ASIACRYPT 2023, J. Guo and R. Steinfeld, Eds., Singapore: Springer Nature Singapore, pp. 342–373, 2023. https://doi.org/10.1007/978-981-99-8733-7_11
[3] J. Alwen, G. Fuchsbauer, and M. Mularczyk, “Updatable Public-Key Encryption, Revisited,” Advances in Cryptology – EUROCRYPT 2024, M. Joye and G. Leander, Eds., Cham: Springer Nature Switzerland, pp. 346–376, 2024. https://doi.org/10.1007/978-3-031-58754-2_13
[4] M. Prerna, A. Sachdeva, and P. Mahajan, “A Study of Encryption Algorithms AES, DES and RSA for Security,” Type: Double Blind Peer Reviewed International Research Journal Publisher: Global Journals Inc, vol. 13, 2013.
[5] M. A. Al-Shabi, “A survey on symmetric and asymmetric cryptography algorithms in information security,” International Journal of Scientific and Research Publications (IJSRP), vol. 9, no. 3, pp. 576–589, 2019. http://dx.doi.org/10.29322/IJSRP.X.X.2018.pXXXX
[6] C. Ganesh, B. Magri, and D. Venturi, “Cryptographic reverse firewalls for interactive proof systems,” Theor. Comput. Sci., vol. 855, pp. 104–132, 2021. https://doi.org/10.1016/j.tcs.2020.11.043
[7] R. Behnia, A. A. Yavuz, M. O. Ozmen, and T. H. Yuen, “Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT,” Information Security, W. Susilo, R. H. Deng, F. Guo, Y. Li, and R. Intan, Eds., Cham: Springer International Publishing, 2020, pp. 39–58.
[8] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing,” Advances in Cryptology — CRYPTO 2001, J. Kilian, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2001, pp. 213–229. https://doi.org/10.1007/3-540-44647-8_13
[9] S. S. Al-Riyami and K. G. Paterson, “Certificateless Public Key Cryptography,” pp. 452–473, 2003. https://doi.org/10.1007/978-3-540-40061-5_29
[10] T.-Y. Wu, C.-M. Chen, K.-H. Wang, C. Meng, and E. K. Wang, “A provably secure certificateless public key encryption with keyword search,” Journal of the Chinese Institute of Engineers, vol. 42, no. 1, pp. 20–28, 2019. https://doi.org/10.1080/02533839.2018.1537807
[11] A. W. Dent, “A survey of certificateless encryption schemes and security models,” Int. J. Inf. Secur., vol. 7, no. 5, pp. 349–377, 2008. https://doi.org/10.1007/s10207-008-0055-0
[12] M. Backes, A. Kate, and A. Patra, “Computational Verifiable Secret Sharing Revisited,” in Advances in Cryptology – ASIACRYPT 2011, D. H. Lee and X. Wang, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 590–609, 2011. https://doi.org/10.1007/978-3-642-25385-0_32
[13] I. Mironov and N. Stephens-Davidowitz, “Cryptographic Reverse Firewalls,” Advances in Cryptology - EUROCRYPT 2015, M. Oswald Elisabeth and Fischlin, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 657–686, 2015. https://doi.org/10.1007/978-3-662-46803-6_22
[14] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, p. 101754, 2020. https://doi.org/10.1016/j.sysarc.2020.101754
[15] S. Ullah, J. Zheng, N. Din, M. T. Hussain, F. Ullah, and M. Yousaf, “Elliptic Curve Cryptography; Applications, challenges, recent advances, and future trends: A comprehensive survey,” Comput. Sci. Rev., vol. 47, p. 100530, 2023. https://doi.org/10.1016/j.cosrev.2022.100530
[16] A. Bossuat, X. Bultel, P.-A. Fouque, C. Onete, and T. van der Merwe, “Designing Reverse Firewalls for the Real World,” in Computer Security – ESORICS 2020, L. Chen, N. Li, K. Liang, and S. Schneider, Eds., Cham: Springer International Publishing, pp. 193–213, 2020. https://doi.org/10.1007/978-3-030-58951-6_10
[17] M. Ouyang, Z. Wang, and F. Li, “Digital signature with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 116, p. 102029, 2021. https://doi.org/10.1016/j.sysarc.2021.102029
[18] N. Eltayieb, R. Elhabob, A. M. S. Abdelgader, Y. Liao, F. Li, and S. Zhou, “Certificateless Proxy Re-encryption with Cryptographic Reverse Firewalls for Secure Cloud Data Sharing,” Future Generation Computer Systems, vol. 162, p. 107478, 2025. https://doi.org/10.1016/j.future.2024.08.002
[19] “Cryptography and Network Security.” [Online]. Available: www.riverpublishers.com
[20] D. A. McGrew and J. Viega, “The Security and Performance of the Galois/Counter Mode (GCM) of Operation,” Progress in Cryptology - INDOCRYPT 2004, A. Canteaut and K. Viswanathan, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 343–355, 2004. https://doi.org/10.1007/978-3-540-30556-9_27
[21] D. Hankerson, S. Vanstone, and A. Menezes, Eds., “Elliptic Curve Arithmetic,” Guide to Elliptic Curve Cryptography, New York: Springer-Verlag, pp. 75–152, 2004. https://doi.org/10.1007/0-387-21846-7_3
[22] A. Karmakar, S. S. Roy, O. Reparaz, F. Vercauteren, and I. Verbauwhede, “Constant-Time Discrete Gaussian Sampling,” IEEE Transactions on Computers, vol. 67, no. 11, pp. 1561–1571, 2018. https://doi.org/10.1109/TC.2018.2814587
[23] R. Elhabob, M. Taha, H. Xiong, M. K. Khan, S. Kumari, and P. Chaudhary, “Pairing-free certificateless public key encryption with equality test for Internet of Vehicles,” Computers and Electrical Engineering, vol. 116, p. 109140, 2024. https://doi.org/10.1016/j.compeleceng.2024.109140
[24] M. Ma, M. Luo, S. Fan, and D. Feng, “An Efficient Pairing-Free Certificateless Searchable Public Key Encryption for Cloud-Based IIoT,” Wirel. Commun. Mob. Comput., vol. 2020, no. 1, p. 8850520, 2020. https://doi.org/10.1155/2020/8850520
[25] C. Gentry, “Practical Identity-Based Encryption Without Random Oracles,” Advances in Cryptology - EUROCRYPT, S. Vaudenay, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 445–464, 2006. https://doi.org/10.1007/11761679_27
[26] D. He, M. Ma, S. Zeadally, N. Kumar, and K. Liang, “Certificateless Public Key Authenticated Encryption With Keyword Search for Industrial Internet of Things,” IEEE Trans. Industr. Inform., vol. 14, no. 8, pp. 3618–3627, 2018. https://doi.org/10.1109/TII.2017.2771382
[27] M. Ma, D. He, S. Fan, and D. Feng, “Certificateless searchable public key encryption scheme secure against keyword guessing attacks for smart healthcare,” Journal of Information Security and Applications, vol. 50, p. 102429, 2020. https://doi.org/10.1016/j.jisa.2019.102429
[28] M. R. Senouci, I. Benkhaddra, A. Senouci, and F. Li, “An efficient and secure certificateless searchable encryption scheme against keyword guessing attacks,” Journal of Systems Architecture, vol. 119, p. 102271, 2021. https://doi.org/10.1016/j.sysarc.2021.102271
[29] H.-Y. Lin, C.-W. Yeh, and C.-S. Chen, “Certificateless Proxy Re-Encryption Scheme for the Internet of Medical Things,” Electronics (Basel)., vol. 14, no. 23, p. 4654, 2025. https://doi.org/10.3390/electronics14234654
[30] M. Bellare, J. Jaeger, and D. Kane, “Mass-surveillance without the State,” Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA: ACM, , pp. 1431–1440, 2015. https://doi.org/10.1145/2810103.2813681
[31] L. Arquint et al., “Sound Verification of Security Protocols: From Design to Interoperable Implementations,” 2023 IEEE Symposium on Security and Privacy (SP), IEEE, May 2023, pp. 1077–1093, 2023. https://doi.org/10.1109/SP46215.2023.10179325
[32] M. Ouyang, Q. Sun, and F. Li, “Subversion-Resistant Identity-Based Aggregate Signature with Reverse Firewalls for IoV,” IEEE Trans. Veh. Technol., vol. 74, no. 7, pp. 10841–10852, 2025. https://doi.org/10.1109/TVT.2025.3546642
[33] J. Liu, R. Chen, Y. Wang, X. Tang, and J. Su, “Subversion-Resilient Authenticated Key Exchange with Reverse Firewalls,” in Provable and Practical Security, J. K. Liu, L. Chen, S.-F. Sun, and X. Liu, Eds., Singapore: Springer Nature Singapore, pp. 181–200, 2025. https://doi.org/10.1007/978-981-96-0957-4_10
[34] C. Jin, W. Zhou, L. Li, C. Liu, and X. Chen, “Blockchain-Based Signature Scheme with Cryptographic Reverse Firewalls for IoV,” Frontiers in Cyber Security, H. Yang and R. Lu, Eds., Singapore: Springer Nature Singapore, pp. 82–95, 2024. https://doi.org/10.1007/978-981-99-9331-4_6
[35] M. Bellare and P. Rogaway, “Random Oracles are Practical: A P aradigm for Designing EEcient Protocols,” ACM, 1993. https://doi.org/10.1145/168588
[36] S. S. Al-Riyami and K. G. Paterson, “CBE from CL-PKE: A Generic Construction and Efficient Schemes,” in Public Key Cryptography - PKC 2005, S. Vaudenay, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 398–415, 2005. https://doi.org/10.1007/978-3-540-30580-4_27
[37] T.-T. Tsai and J.-H. Yang, “Leakage-resilient certificateless public key encryption with equality test resistant to side-channel attacks,” Computer Networks, vol. 270, p. 111485, 2025. https://doi.org/10.1016/j.comnet.2025.111485
[38] L. Zhang, B. Qin, Q. Wu, and F. Zhang, “Efficient many-to-one authentication with certificateless aggregate signatures,” Computer Networks, vol. 54, no. 14, pp. 2482–2491, 2010. https://doi.org/10.1016/j.comnet.2010.04.008
[39] C. Jin, H. Zhu, W. Qin, Z. Chen, Y. Jin, and J. Shan, “Heterogeneous online/offline signcryption for secure communication in Internet of Things,” Journal of Systems Architecture, vol. 127, p. 102522, 2022. https://doi.org/10.1016/j.sysarc.2022.102522
[40] N. Yang, C. Tang, and D. He, “Blockchain-Assisted Secure Data Sharing Protocol with a Dynamic Multiuser Keyword Search in IIoT,” IEEE Internet Things J., vol. 10, no. 17, pp. 15749–15760, 2023. https://doi.org/10.1109/JIOT.2023.3264912
[41] E. E. Targhi and D. Unruh, “Post-Quantum Security of the Fujisaki-Okamoto and OAEP Transforms,” Theory of Cryptography, M. Hirt and A. Smith, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 192–216, 2026. https://doi.org/10.1007/978-3-662-53644-5_8
[42] P. S. L. M. Barreto and M. Naehrig, “Pairing-Friendly Elliptic Curves of Prime Order,” Selected Areas in Cryptography, B. Preneel and S. Tavares, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 319–331, 2006. https://doi.org/10.1007/11693383_22
[43] D. F. Aranha, K. Karabina, P. Longa, C. H. Gebotys, and J. López, “Faster Explicit Formulas for Computing Pairings over Ordinary Curves,” in Advances in Cryptology – EUROCRYPT 2011, K. G. Paterson, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 48–68, 2011. https://doi.org/10.1007/978-3-642-20465-4_5
[44] C. Aguilar-Melchor et al., “Batch Signatures, Revisited,” in Topics in Cryptology – CT-RSA 2024, E. Oswald, Ed., Cham: Springer Nature Switzerland, pp. 163–186, 2024. https://doi.org/10.1007/978-3-031-58868-6_7
[45] K. Javeed, A. El-Moursy, and D. Gregg, “EC-Crypto: Highly Efficient Area-Delay Optimized Elliptic Curve Cryptography Processor,” IEEE Access, vol. 11, pp. 56649–56662, 2023. https://doi.org/10.1109/ACCESS.2023.3282781
[46] R. L. Rivest, A. Shamir, and L. Adleman, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems.”
[47] J. Chen, H. W. Lim, S. Ling, H. Wang, and K. Nguyen, “Revocable Identity-Based Encryption from Lattices,” IACR Cryptology ePrint Archive, vol. 2011, pp. 390–403, 2012. https://doi.org/10.1007/978-3-642-31448-3_29
[48] D. Mallick, A. K. Das, M. Wazid, and Y. Park, “Authenticated Certificateless Verifiable Searchable Public Key Encryption Scheme with Big Data Analytics for IoT-Based Healthcare,” IEEE Internet Things J., vol. 12, no. 23, pp. 50978–50996, 2025. https://doi.org/10.1109/JIOT.2025.3611228
[49] C. Peikert, “A Decade of Lattice Cryptography,” Foundations and Trends® in Theoretical Computer Science, vol. 10, no. 4, pp. 283–424, 2016. https://doi.org/10.1561/0400000074
[50] L. Gasser, “Post-quantum Cryptography,” Trends in Data Protection and Encryption Technologies, V. Mulder, A. Mermoud, V. Lenders, and B. Tellenbach, Eds., Cham: Springer Nature Switzerland, pp. 47–52, 2023. https://doi.org/10.1007/978-3-031-33386-6_10
[51] S. Prajapat, D. Gautam, P. Kumar, S. Jangirala, A. Kumar Das, and B. Sikdar, “Secure Lattice-Based Signature Scheme for Internet of Things Applications,” IEEE Access, vol. 13, pp. 75985–75999, 2025. https://doi.org/10.1109/ACCESS.2025.3565200
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Lukman Umar Faruk

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Abstract views: 99
,
PDF Downloads: 1








