An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls

Authors

  • Lukman Umar Faruk Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.
  • Muhammad Bashir Abdulrazaq Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria
  • Zainab Mukhtar Abubakar Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria
  • Zahruddeen Haruna Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria
  • Nafisa Shehu Usman Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.
  • Hassan Maharazu Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

Keywords:

Certificateless Public Key , Encryption, Cryptographic Reverse , Firewalls, IND-CCA2 Security, Bilinear Pairings, Exfiltration Resistance

Abstract

Secure communication in modern distributed environments such as the Internet of Things (IoT), cloud computing, and peer-to-peer systems requires cryptographic schemes that are both efficient and resilient to advanced threats. Traditional approaches such as Public Key Infrastructure (PKI) and Identity-Based Encryption (IBE) suffer from certificate management overhead and key escrow problems, respectively [1], [2]. Certificateless Public Key Encryption (CL-PKE) addresses these limitations but suffers from high computational and communication overheads [3], while Cryptographic Reverse Firewalls (CRFs) provide protection against data exfiltration in compromised systems. To address these challenges, this study developed an optimized CL-PKE-CRF scheme by implementing a single-element public key structure, sender-side precomputation of pairing operations, and independent per-user randomization using a Key Derivation Function at the Key Generation Center. These improvements reduced the redundant operations while maintaining correctness and preventing information leakage. The scheme was implemented using the Charm-Crypto library and evaluated over 1000 iterations across 128-, 192-, and 256-bit security levels. Results show an average reduction of about 25% in computational overhead, 76.6% faster subsequent encryption latency for repeated operations, and a 33% decrease in communication cost compared to the baseline model. Security analysis confirms that the scheme achieves IND-CCA2 security with negligible adversarial advantage (< 0.004) and 100% decryption correctness with zero leakage in all simulated compromise scenarios and provides strong resistance to exfiltration attacks. Overall, the developed CL-PKE-CRF scheme offers a practical and efficient solution for secure communication, particularly in resource-constrained environments such as IoT and distributed systems.

Author Biographies

Lukman Umar Faruk, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

mceclip2-99625bbdc047ac39e0da16cdc0ccf47f.png

Lukman Umar Faruk is a postgraduate student in the Department of Computer Engineering, Ahmadu Bello University, Zaria, Nigeria. He obtained his B.Eng. in Electrical Engineering from Ahmadu Bello University in 2016. His research interests include applied cryptography, certificateless encryption, and post-Snowden security. He can be contacted at [email protected]. ORCID: https://orcid.org/ 0009-0001-9297-7913

Muhammad Bashir Abdulrazaq, Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

mceclip0-84caa6b3a37566f0ae34cdd64a43ce31.png

Muhammad Bashir Abdulrazaq: is a lecturer in the Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria. He can be contacted at [email protected].

Zainab Mukhtar Abubakar, Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria

Zahruddeen Haruna, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria

mceclip1-3c10ca88b303f8e96959080e9b5734d3.png

Zahruddeen Haruna: is a lecturer in the Department of Computer Engineering at Ahmadu Bello University, Zaria, Nigeria. He earned his BEng Degree from Electrical Engineering Department Ahmadu Bello University, Zaria, Nigeria, in 2011, MSc, and Ph.D. degrees from Computer Engineering Department, Ahmadu Bello University, Zaria, Nigeria, in 2017 and 2024. He specializes in various aspects of computer engineering. His primary research focus is in Control Engineering, where he explores the development and optimization of control systems for different applications. He is dedicated to advancing his research and contributing to academic knowledge in this field.

Nafisa Shehu Usman, Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

Department of Computer Engineering, Faculty of Engineering, Ahmadu Bello University Zaria, Kaduna state, Nigeria.

Hassan Maharazu, Department of Electrical and Electronics Engineering, Federal University of Transportation, Daura Katsina state, Nigeria

Hassan Maharazu: is a lecturer at Federal University of Transportation Daura and also a postgraduate student in the Department of Computer Engineering, Ahmadu Bello University, Zaria, Nigeria. He obtained his B.Eng. in Electrical Engineering from Ahmadu Bello University in 2015 and MSc. Computer Engineering in 2025. His research interests include designing of adaptive controller. He can be contacted at [email protected].

References

[1] C. Abou Haidar, A. Passelègue, and D. Stehlé, “Efficient Updatable Public-Key Encryption from Lattices,” in Advances in Cryptology – ASIACRYPT 2023, J. Guo and R. Steinfeld, Eds., Singapore: Springer Nature Singapore, 2023, pp. 342–373.

[2] R. Behnia, A. A. Yavuz, M. O. Ozmen, and T. H. Yuen, “Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT,” in Information Security, W. Susilo, R. H. Deng, F. Guo, Y. Li, and R. Intan, Eds., Cham: Springer International Publishing, 2020, pp. 39–58.

[3] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, Oct. 2020, doi: 10.1016/j.sysarc.2020.101754.

[4] J. Alwen, G. Fuchsbauer, and M. Mularczyk, “Updatable Public-Key Encryption, Revisited,” in Advances in Cryptology – EUROCRYPT 2024, M. Joye and G. Leander, Eds., Cham: Springer Nature Switzerland, 2024, pp. 346–376.

[5] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing,” in Advances in Cryptology — CRYPTO 2001, J. Kilian, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2001, pp. 213–229.

[6] S. S. Al-Riyami and K. G. Paterson, “Certificateless Public Key Cryptography.”

[7] M. Ouyang, Z. Wang, and F. Li, “Digital signature with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 116, p. 102029, 2021, doi: https://doi.org/10.1016/j.sysarc.2021.102029.

[8] S. Ullah, J. Zheng, N. Din, M. T. Hussain, F. Ullah, and M. Yousaf, “Elliptic Curve Cryptography; Applications, challenges, recent advances, and future trends: A comprehensive survey,” Comput. Sci. Rev., vol. 47, p. 100530, 2023, doi: https://doi.org/10.1016/j.cosrev.2022.100530.

[9] C. Ganesh, B. Magri, and D. Venturi, “Cryptographic reverse firewalls for interactive proof systems,” Theor. Comput. Sci., vol. 855, pp. 104–132, 2021, doi: https://doi.org/10.1016/j.tcs.2020.11.043.

[10] R. Elhabob, M. Taha, H. Xiong, M. K. Khan, S. Kumari, and P. Chaudhary, “Pairing-free certificateless public key encryption with equality test for Internet of Vehicles,” Computers and Electrical Engineering, vol. 116, p. 109140, 2024, doi: https://doi.org/10.1016/j.compeleceng.2024.109140.

[11] M. Ma, M. Luo, S. Fan, and D. Feng, “An Efficient Pairing-Free Certificateless Searchable Public Key Encryption for Cloud-Based IIoT,” Wirel. Commun. Mob. Comput., vol. 2020, no. 1, p. 8850520, 2020, doi: https://doi.org/10.1155/2020/8850520.

[12] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, Oct. 2020, doi: 10.1016/j.sysarc.2020.101754.

[13] N. Eltayieb, R. Elhabob, A. M. S. Abdelgader, Y. Liao, F. Li, and S. Zhou, “Certificateless Proxy Re-encryption with Cryptographic Reverse Firewalls for Secure Cloud Data Sharing,” Future Generation Computer Systems, vol. 162, p. 107478, 2025, doi: https://doi.org/10.1016/j.future.2024.08.002.

[14] A. Bossuat, X. Bultel, P.-A. Fouque, C. Onete, and T. van der Merwe, “Designing Reverse Firewalls for the Real World,” in Computer Security – ESORICS 2020, L. Chen, N. Li, K. Liang, and S. Schneider, Eds., Cham: Springer International Publishing, 2020, pp. 193–213.

Published

2026-08-06

How to Cite

[1]
L. Umar Faruk, M. Bashir Abdulrazaq, Z. Mukhtar Abubakar, Z. Haruna, N. Shehu Usman, and H. Maharazu, “An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls”, Vokasi UNESA Bull. Eng. Technol. Appl. Sci., vol. 3, no. 3, Aug. 2026.
Abstract views: 72

Most read articles by the same author(s)

Similar Articles

1 2 3 4 > >> 

You may also start an advanced similarity search for this article.