An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls

Authors

  • Lukman Umar Faruk Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.
  • Muhammad Bashir Abdulrazaq Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria
  • Zainab Mukhtar Abubakar Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria
  • Zahruddeen Haruna Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria
  • A. Umar Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria
  • Nafisa Shehu Usman Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.
  • Hassan Maharazu Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

DOI:

https://doi.org/10.26740/vubeta.v3i3.52993

Keywords:

Certificateless Public Key , Encryption, Cryptographic Reverse , Firewalls, IND-CCA2 Security, Bilinear Pairings, Exfiltration Resistance

Abstract

Secure communication in Internet of Things (IoT), cloud computing, and peer-to-peer environments requires efficient cryptographic schemes resilient to advanced threats. Public Key Infrastructure (PKI) incurs certificate management overhead, while Identity-Based Encryption (IBE) introduces key escrow. Certificateless Public Key Encryption (CL-PKE) addresses these limitations, but existing constructions integrating Cryptographic Reverse Firewalls (CRFs) remain computationally expensive and lack IND-CCA2 security guarantees. This study develops an optimized CL-PKE-CRF scheme using a single-element public key, sender-side precomputation of pairing operations, and independent per-user randomization through a Key Derivation Function (KDF) at the Key Generation Center (KGC). The scheme was implemented using Charm-Crypto and evaluated over 1,000 iterations at 128-, 192-, and 256-bit security levels. Compared with the baseline, it reduced computational overhead by approximately 25% and communication costs by 33%, while subsequent encryption latency decreased by 76.6% for repeated operations. Simulated evaluations reported adversarial advantage below 0.004, 100% decryption correctness, and no observed information leakage across the tested compromise scenarios. A formal IND-CCA2 security reduction under the Computational Bilinear Diffie-Hellman (CBDH) assumption in the random oracle model is also presented. These findings demonstrate improved efficiency and resistance to exfiltration attacks, supporting secure communication in resource-constrained environments.

Author Biographies

Lukman Umar Faruk, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

mceclip2-99625bbdc047ac39e0da16cdc0ccf47f.png

Lukman Umar Faruk is a postgraduate student in the Department of Computer Engineering, Ahmadu Bello University, Zaria, Nigeria. He obtained his B.Eng. in Electrical Engineering from Ahmadu Bello University in 2016. His research interests include applied cryptography, certificateless encryption, and post-Snowden security. He can be contacted at [email protected]. ORCID: https://orcid.org/ 0009-0001-9297-7913

Muhammad Bashir Abdulrazaq, Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

mceclip0-84caa6b3a37566f0ae34cdd64a43ce31.png

Muhammad Bashir Abdulrazaq: is a lecturer in the Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria. He can be contacted at [email protected].

Zainab Mukhtar Abubakar, Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

Zahruddeen Haruna, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria

mceclip1-3c10ca88b303f8e96959080e9b5734d3.png

Zahruddeen Haruna: is a lecturer in the Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria. He earned his BEng Degree from Electrical Engineering Department Ahmadu Bello University, Zaria, Nigeria, in 2011, MSc, and Ph.D. degrees from Computer Engineering Department, Ahmadu Bello University, Zaria, Nigeria, in 2017 and 2024. He specializes in various aspects of computer engineering. His primary research focus is in Control Engineering, where he explores the development and optimization of control systems for different applications. He is dedicated to advancing his research and contributing to academic knowledge in this field.

A. Umar, Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

Nafisa Shehu Usman, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

Hassan Maharazu, Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

Hassan Maharazu: is a lecturer at Federal University of Transportation Daura and also a postgraduate student in the Department of Computer Engineering, Ahmadu Bello University, Zaria, Nigeria. He obtained his B.Eng. in Electrical Engineering from Ahmadu Bello University in 2015 and MSc. Computer Engineering in 2025. His research interests include designing of adaptive controller. He can be contacted at [email protected].

References

[1] M. Idris Abubakar, A. Ore-Ofe, A. Umar, I. Ibrahim, L. A. Olugbenga, and A. Abdulbasit Abiola, “Design of an Enterprise Network Terminal Security Solution,” Vokasi Unesa Bulletin of Engineering, Technology and Applied Science, vol. 2, no. 3, pp. 412–427, Aug. 2025. https://doi.org/10.26740/vubeta.v2i3.39105

[2] C. Abou Haidar, A. Passelègue, and D. Stehlé, “Efficient Updatable Public-Key Encryption from Lattices,” in Advances in Cryptology – ASIACRYPT 2023, J. Guo and R. Steinfeld, Eds., Singapore: Springer Nature Singapore, pp. 342–373, 2023. https://doi.org/10.1007/978-981-99-8733-7_11

[3] J. Alwen, G. Fuchsbauer, and M. Mularczyk, “Updatable Public-Key Encryption, Revisited,” Advances in Cryptology – EUROCRYPT 2024, M. Joye and G. Leander, Eds., Cham: Springer Nature Switzerland, pp. 346–376, 2024. https://doi.org/10.1007/978-3-031-58754-2_13

[4] M. Prerna, A. Sachdeva, and P. Mahajan, “A Study of Encryption Algorithms AES, DES and RSA for Security,” Type: Double Blind Peer Reviewed International Research Journal Publisher: Global Journals Inc, vol. 13, 2013.

[5] M. A. Al-Shabi, “A survey on symmetric and asymmetric cryptography algorithms in information security,” International Journal of Scientific and Research Publications (IJSRP), vol. 9, no. 3, pp. 576–589, 2019. http://dx.doi.org/10.29322/IJSRP.X.X.2018.pXXXX

[6] C. Ganesh, B. Magri, and D. Venturi, “Cryptographic reverse firewalls for interactive proof systems,” Theor. Comput. Sci., vol. 855, pp. 104–132, 2021. https://doi.org/10.1016/j.tcs.2020.11.043

[7] R. Behnia, A. A. Yavuz, M. O. Ozmen, and T. H. Yuen, “Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT,” Information Security, W. Susilo, R. H. Deng, F. Guo, Y. Li, and R. Intan, Eds., Cham: Springer International Publishing, 2020, pp. 39–58.

[8] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing,” Advances in Cryptology — CRYPTO 2001, J. Kilian, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2001, pp. 213–229. https://doi.org/10.1007/3-540-44647-8_13

[9] S. S. Al-Riyami and K. G. Paterson, “Certificateless Public Key Cryptography,” pp. 452–473, 2003. https://doi.org/10.1007/978-3-540-40061-5_29

[10] T.-Y. Wu, C.-M. Chen, K.-H. Wang, C. Meng, and E. K. Wang, “A provably secure certificateless public key encryption with keyword search,” Journal of the Chinese Institute of Engineers, vol. 42, no. 1, pp. 20–28, 2019. https://doi.org/10.1080/02533839.2018.1537807

[11] A. W. Dent, “A survey of certificateless encryption schemes and security models,” Int. J. Inf. Secur., vol. 7, no. 5, pp. 349–377, 2008. https://doi.org/10.1007/s10207-008-0055-0

[12] M. Backes, A. Kate, and A. Patra, “Computational Verifiable Secret Sharing Revisited,” in Advances in Cryptology – ASIACRYPT 2011, D. H. Lee and X. Wang, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 590–609, 2011. https://doi.org/10.1007/978-3-642-25385-0_32

[13] I. Mironov and N. Stephens-Davidowitz, “Cryptographic Reverse Firewalls,” Advances in Cryptology - EUROCRYPT 2015, M. Oswald Elisabeth and Fischlin, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 657–686, 2015. https://doi.org/10.1007/978-3-662-46803-6_22

[14] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, p. 101754, 2020. https://doi.org/10.1016/j.sysarc.2020.101754

[15] S. Ullah, J. Zheng, N. Din, M. T. Hussain, F. Ullah, and M. Yousaf, “Elliptic Curve Cryptography; Applications, challenges, recent advances, and future trends: A comprehensive survey,” Comput. Sci. Rev., vol. 47, p. 100530, 2023. https://doi.org/10.1016/j.cosrev.2022.100530

[16] A. Bossuat, X. Bultel, P.-A. Fouque, C. Onete, and T. van der Merwe, “Designing Reverse Firewalls for the Real World,” in Computer Security – ESORICS 2020, L. Chen, N. Li, K. Liang, and S. Schneider, Eds., Cham: Springer International Publishing, pp. 193–213, 2020. https://doi.org/10.1007/978-3-030-58951-6_10

[17] M. Ouyang, Z. Wang, and F. Li, “Digital signature with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 116, p. 102029, 2021. https://doi.org/10.1016/j.sysarc.2021.102029

[18] N. Eltayieb, R. Elhabob, A. M. S. Abdelgader, Y. Liao, F. Li, and S. Zhou, “Certificateless Proxy Re-encryption with Cryptographic Reverse Firewalls for Secure Cloud Data Sharing,” Future Generation Computer Systems, vol. 162, p. 107478, 2025. https://doi.org/10.1016/j.future.2024.08.002

[19] “Cryptography and Network Security.” [Online]. Available: www.riverpublishers.com

[20] D. A. McGrew and J. Viega, “The Security and Performance of the Galois/Counter Mode (GCM) of Operation,” Progress in Cryptology - INDOCRYPT 2004, A. Canteaut and K. Viswanathan, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 343–355, 2004. https://doi.org/10.1007/978-3-540-30556-9_27

[21] D. Hankerson, S. Vanstone, and A. Menezes, Eds., “Elliptic Curve Arithmetic,” Guide to Elliptic Curve Cryptography, New York: Springer-Verlag, pp. 75–152, 2004. https://doi.org/10.1007/0-387-21846-7_3

[22] A. Karmakar, S. S. Roy, O. Reparaz, F. Vercauteren, and I. Verbauwhede, “Constant-Time Discrete Gaussian Sampling,” IEEE Transactions on Computers, vol. 67, no. 11, pp. 1561–1571, 2018. https://doi.org/10.1109/TC.2018.2814587

[23] R. Elhabob, M. Taha, H. Xiong, M. K. Khan, S. Kumari, and P. Chaudhary, “Pairing-free certificateless public key encryption with equality test for Internet of Vehicles,” Computers and Electrical Engineering, vol. 116, p. 109140, 2024. https://doi.org/10.1016/j.compeleceng.2024.109140

[24] M. Ma, M. Luo, S. Fan, and D. Feng, “An Efficient Pairing-Free Certificateless Searchable Public Key Encryption for Cloud-Based IIoT,” Wirel. Commun. Mob. Comput., vol. 2020, no. 1, p. 8850520, 2020. https://doi.org/10.1155/2020/8850520

[25] C. Gentry, “Practical Identity-Based Encryption Without Random Oracles,” Advances in Cryptology - EUROCRYPT, S. Vaudenay, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 445–464, 2006. https://doi.org/10.1007/11761679_27

[26] D. He, M. Ma, S. Zeadally, N. Kumar, and K. Liang, “Certificateless Public Key Authenticated Encryption With Keyword Search for Industrial Internet of Things,” IEEE Trans. Industr. Inform., vol. 14, no. 8, pp. 3618–3627, 2018. https://doi.org/10.1109/TII.2017.2771382

[27] M. Ma, D. He, S. Fan, and D. Feng, “Certificateless searchable public key encryption scheme secure against keyword guessing attacks for smart healthcare,” Journal of Information Security and Applications, vol. 50, p. 102429, 2020. https://doi.org/10.1016/j.jisa.2019.102429

[28] M. R. Senouci, I. Benkhaddra, A. Senouci, and F. Li, “An efficient and secure certificateless searchable encryption scheme against keyword guessing attacks,” Journal of Systems Architecture, vol. 119, p. 102271, 2021. https://doi.org/10.1016/j.sysarc.2021.102271

[29] H.-Y. Lin, C.-W. Yeh, and C.-S. Chen, “Certificateless Proxy Re-Encryption Scheme for the Internet of Medical Things,” Electronics (Basel)., vol. 14, no. 23, p. 4654, 2025. https://doi.org/10.3390/electronics14234654

[30] M. Bellare, J. Jaeger, and D. Kane, “Mass-surveillance without the State,” Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA: ACM, , pp. 1431–1440, 2015. https://doi.org/10.1145/2810103.2813681

[31] L. Arquint et al., “Sound Verification of Security Protocols: From Design to Interoperable Implementations,” 2023 IEEE Symposium on Security and Privacy (SP), IEEE, May 2023, pp. 1077–1093, 2023. https://doi.org/10.1109/SP46215.2023.10179325

[32] M. Ouyang, Q. Sun, and F. Li, “Subversion-Resistant Identity-Based Aggregate Signature with Reverse Firewalls for IoV,” IEEE Trans. Veh. Technol., vol. 74, no. 7, pp. 10841–10852, 2025. https://doi.org/10.1109/TVT.2025.3546642

[33] J. Liu, R. Chen, Y. Wang, X. Tang, and J. Su, “Subversion-Resilient Authenticated Key Exchange with Reverse Firewalls,” in Provable and Practical Security, J. K. Liu, L. Chen, S.-F. Sun, and X. Liu, Eds., Singapore: Springer Nature Singapore, pp. 181–200, 2025. https://doi.org/10.1007/978-981-96-0957-4_10

[34] C. Jin, W. Zhou, L. Li, C. Liu, and X. Chen, “Blockchain-Based Signature Scheme with Cryptographic Reverse Firewalls for IoV,” Frontiers in Cyber Security, H. Yang and R. Lu, Eds., Singapore: Springer Nature Singapore, pp. 82–95, 2024. https://doi.org/10.1007/978-981-99-9331-4_6

[35] M. Bellare and P. Rogaway, “Random Oracles are Practical: A P aradigm for Designing EEcient Protocols,” ACM, 1993. https://doi.org/10.1145/168588

[36] S. S. Al-Riyami and K. G. Paterson, “CBE from CL-PKE: A Generic Construction and Efficient Schemes,” in Public Key Cryptography - PKC 2005, S. Vaudenay, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 398–415, 2005. https://doi.org/10.1007/978-3-540-30580-4_27

[37] T.-T. Tsai and J.-H. Yang, “Leakage-resilient certificateless public key encryption with equality test resistant to side-channel attacks,” Computer Networks, vol. 270, p. 111485, 2025. https://doi.org/10.1016/j.comnet.2025.111485

[38] L. Zhang, B. Qin, Q. Wu, and F. Zhang, “Efficient many-to-one authentication with certificateless aggregate signatures,” Computer Networks, vol. 54, no. 14, pp. 2482–2491, 2010. https://doi.org/10.1016/j.comnet.2010.04.008

[39] C. Jin, H. Zhu, W. Qin, Z. Chen, Y. Jin, and J. Shan, “Heterogeneous online/offline signcryption for secure communication in Internet of Things,” Journal of Systems Architecture, vol. 127, p. 102522, 2022. https://doi.org/10.1016/j.sysarc.2022.102522

[40] N. Yang, C. Tang, and D. He, “Blockchain-Assisted Secure Data Sharing Protocol with a Dynamic Multiuser Keyword Search in IIoT,” IEEE Internet Things J., vol. 10, no. 17, pp. 15749–15760, 2023. https://doi.org/10.1109/JIOT.2023.3264912

[41] E. E. Targhi and D. Unruh, “Post-Quantum Security of the Fujisaki-Okamoto and OAEP Transforms,” Theory of Cryptography, M. Hirt and A. Smith, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 192–216, 2026. https://doi.org/10.1007/978-3-662-53644-5_8

[42] P. S. L. M. Barreto and M. Naehrig, “Pairing-Friendly Elliptic Curves of Prime Order,” Selected Areas in Cryptography, B. Preneel and S. Tavares, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 319–331, 2006. https://doi.org/10.1007/11693383_22

[43] D. F. Aranha, K. Karabina, P. Longa, C. H. Gebotys, and J. López, “Faster Explicit Formulas for Computing Pairings over Ordinary Curves,” in Advances in Cryptology – EUROCRYPT 2011, K. G. Paterson, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 48–68, 2011. https://doi.org/10.1007/978-3-642-20465-4_5

[44] C. Aguilar-Melchor et al., “Batch Signatures, Revisited,” in Topics in Cryptology – CT-RSA 2024, E. Oswald, Ed., Cham: Springer Nature Switzerland, pp. 163–186, 2024. https://doi.org/10.1007/978-3-031-58868-6_7

[45] K. Javeed, A. El-Moursy, and D. Gregg, “EC-Crypto: Highly Efficient Area-Delay Optimized Elliptic Curve Cryptography Processor,” IEEE Access, vol. 11, pp. 56649–56662, 2023. https://doi.org/10.1109/ACCESS.2023.3282781

[46] R. L. Rivest, A. Shamir, and L. Adleman, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems.”

[47] J. Chen, H. W. Lim, S. Ling, H. Wang, and K. Nguyen, “Revocable Identity-Based Encryption from Lattices,” IACR Cryptology ePrint Archive, vol. 2011, pp. 390–403, 2012. https://doi.org/10.1007/978-3-642-31448-3_29

[48] D. Mallick, A. K. Das, M. Wazid, and Y. Park, “Authenticated Certificateless Verifiable Searchable Public Key Encryption Scheme with Big Data Analytics for IoT-Based Healthcare,” IEEE Internet Things J., vol. 12, no. 23, pp. 50978–50996, 2025. https://doi.org/10.1109/JIOT.2025.3611228

[49] C. Peikert, “A Decade of Lattice Cryptography,” Foundations and Trends® in Theoretical Computer Science, vol. 10, no. 4, pp. 283–424, 2016. https://doi.org/10.1561/0400000074

[50] L. Gasser, “Post-quantum Cryptography,” Trends in Data Protection and Encryption Technologies, V. Mulder, A. Mermoud, V. Lenders, and B. Tellenbach, Eds., Cham: Springer Nature Switzerland, pp. 47–52, 2023. https://doi.org/10.1007/978-3-031-33386-6_10

[51] S. Prajapat, D. Gautam, P. Kumar, S. Jangirala, A. Kumar Das, and B. Sikdar, “Secure Lattice-Based Signature Scheme for Internet of Things Applications,” IEEE Access, vol. 13, pp. 75985–75999, 2025. https://doi.org/10.1109/ACCESS.2025.3565200

Downloads

Published

2026-09-11

How to Cite

[1]
L. Umar Faruk, “An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls”, Vokasi UNESA Bull. Eng. Technol. Appl. Sci., vol. 3, no. 3, pp. 517–528, Sep. 2026.
Abstract views: 99 , PDF Downloads: 1

Most read articles by the same author(s)

Similar Articles

1 2 3 4 > >> 

You may also start an advanced similarity search for this article.