An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls

Authors

  • Lukman Umar Faruk Student

DOI:

https://doi.org/10.26740/vubeta.v3i3.52993

Keywords:

Certificateless Public Key , Encryption, Cryptographic Reverse , Firewalls, IND-CCA2 Security, Bilinear Pairings, Exfiltration Resistance

Abstract

Secure communication in modern distributed environments such as the Internet of Things (IoT), cloud computing, and peer-to-peer systems requires cryptographic schemes that are both efficient and resilient to advanced threats. Traditional approaches such as Public Key Infrastructure (PKI) and Identity-Based Encryption (IBE) suffer from certificate management overhead and key escrow problems, respectively [1], [2]. Certificateless Public Key Encryption (CL-PKE) addresses these limitations but suffers from high computational and communication overheads [3], while Cryptographic Reverse Firewalls (CRFs) provide protection against data exfiltration in compromised systems. To address these challenges, this study developed an optimized CL-PKE-CRF scheme by implementing a single-element public key structure, sender-side precomputation of pairing operations, and independent per-user randomization using a Key Derivation Function at the Key Generation Center. These improvements reduced the redundant operations while maintaining correctness and preventing information leakage. The scheme was implemented using the Charm-Crypto library and evaluated over 1000 iterations across 128-, 192-, and 256-bit security levels. Results show an average reduction of about 25% in computational overhead, 76.6% faster subsequent encryption latency for repeated operations, and a 33% decrease in communication cost compared to the baseline model. Security analysis confirms that the scheme achieves IND-CCA2 security with negligible adversarial advantage (< 0.004) and 100% decryption correctness with zero leakage in all simulated compromise scenarios and provides strong resistance to exfiltration attacks. Overall, the developed CL-PKE-CRF scheme offers a practical and efficient solution for secure communication, particularly in resource-constrained environments such as IoT and distributed systems.

References

[1] C. Abou Haidar, A. Passelègue, and D. Stehlé, “Efficient Updatable Public-Key Encryption from Lattices,” in Advances in Cryptology – ASIACRYPT 2023, J. Guo and R. Steinfeld, Eds., Singapore: Springer Nature Singapore, 2023, pp. 342–373.

[2] R. Behnia, A. A. Yavuz, M. O. Ozmen, and T. H. Yuen, “Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT,” in Information Security, W. Susilo, R. H. Deng, F. Guo, Y. Li, and R. Intan, Eds., Cham: Springer International Publishing, 2020, pp. 39–58.

[3] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, Oct. 2020, doi: 10.1016/j.sysarc.2020.101754.

[4] J. Alwen, G. Fuchsbauer, and M. Mularczyk, “Updatable Public-Key Encryption, Revisited,” in Advances in Cryptology – EUROCRYPT 2024, M. Joye and G. Leander, Eds., Cham: Springer Nature Switzerland, 2024, pp. 346–376.

[5] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing,” in Advances in Cryptology — CRYPTO 2001, J. Kilian, Ed., Berlin, Heidelberg: Springer Berlin Heidelberg, 2001, pp. 213–229.

[6] S. S. Al-Riyami and K. G. Paterson, “Certificateless Public Key Cryptography.”

[7] M. Ouyang, Z. Wang, and F. Li, “Digital signature with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 116, p. 102029, 2021, doi: https://doi.org/10.1016/j.sysarc.2021.102029.

[8] S. Ullah, J. Zheng, N. Din, M. T. Hussain, F. Ullah, and M. Yousaf, “Elliptic Curve Cryptography; Applications, challenges, recent advances, and future trends: A comprehensive survey,” Comput. Sci. Rev., vol. 47, p. 100530, 2023, doi: https://doi.org/10.1016/j.cosrev.2022.100530.

[9] C. Ganesh, B. Magri, and D. Venturi, “Cryptographic reverse firewalls for interactive proof systems,” Theor. Comput. Sci., vol. 855, pp. 104–132, 2021, doi: https://doi.org/10.1016/j.tcs.2020.11.043.

[10] R. Elhabob, M. Taha, H. Xiong, M. K. Khan, S. Kumari, and P. Chaudhary, “Pairing-free certificateless public key encryption with equality test for Internet of Vehicles,” Computers and Electrical Engineering, vol. 116, p. 109140, 2024, doi: https://doi.org/10.1016/j.compeleceng.2024.109140.

[11] M. Ma, M. Luo, S. Fan, and D. Feng, “An Efficient Pairing-Free Certificateless Searchable Public Key Encryption for Cloud-Based IIoT,” Wirel. Commun. Mob. Comput., vol. 2020, no. 1, p. 8850520, 2020, doi: https://doi.org/10.1155/2020/8850520.

[12] Y. Zhou, J. Guo, and F. Li, “Certificateless public key encryption with cryptographic reverse firewalls,” Journal of Systems Architecture, vol. 109, Oct. 2020, doi: 10.1016/j.sysarc.2020.101754.

[13] N. Eltayieb, R. Elhabob, A. M. S. Abdelgader, Y. Liao, F. Li, and S. Zhou, “Certificateless Proxy Re-encryption with Cryptographic Reverse Firewalls for Secure Cloud Data Sharing,” Future Generation Computer Systems, vol. 162, p. 107478, 2025, doi: https://doi.org/10.1016/j.future.2024.08.002.

[14] A. Bossuat, X. Bultel, P.-A. Fouque, C. Onete, and T. van der Merwe, “Designing Reverse Firewalls for the Real World,” in Computer Security – ESORICS 2020, L. Chen, N. Li, K. Liang, and S. Schneider, Eds., Cham: Springer International Publishing, 2020, pp. 193–213.

Published

2026-08-06

How to Cite

[1]
L. Umar Faruk, “An Efficient IND-CCA2-Secure Certificateless Public Key Encryption Scheme with Cryptographic Reverse Firewalls”, Vokasi UNESA Bull. Eng. Technol. Appl. Sci., vol. 3, no. 3, Aug. 2026.
Abstract views: 0

Similar Articles

<< < 1 2 3 4 

You may also start an advanced similarity search for this article.