The notion of aggregator oblivious (AO) security for privacy preserving data aggregation was formalized with a specific construction of AO-secure blinding technique over a cyclic group by Shi et al. Some of proposals of data aggregation protocols use the blinding technique of Shi et al. for BGN cryptosystem, an additive homomorphic encryption. Previously, there have been some security analysis on some of BGN based data aggregation protocols in the context of integrity or authenticity of data. Even with such security analysis, the BGN cryptosystem has been a popular building block of privacy preserving data aggregation protocol. In this paper, we study the privacy issues in the blinding technique of Shi et al. used for BGN cryptosystem. We show that the blinding techniques for the BGN cryptosystem used in several protocols are not privacy preserving against the recipient, the decryptor. Our analysis is based on the fact that the BGN cryptosystem uses a pairing e:GxG-->G_T and the existence of the pairing makes the DDH problem on G easy to solve. We also suggest how to prevent such privacy leakage in the blinding technique of Shi et al. used for BGN cryptosystem.
翻译:聚合器不可知(AO)安全概念由Shi等人通过循环群上的AO安全盲化技术具体构造而形式化,旨在实现隐私保护数据聚合。部分数据聚合协议方案采用Shi等人的盲化技术应用于BGN密码系统(一种加法同态加密)。此前,针对基于BGN的数据聚合协议已有部分安全性分析,主要关注数据的完整性或真实性。即便经过此类安全性分析,BGN密码系统仍是隐私保护数据聚合协议广泛使用的构建模块。本文研究Shi等人盲化技术应用于BGN密码系统时的隐私问题。我们证明,在多个协议中用于BGN密码系统的盲化技术无法对接收方(解密方)实现隐私保护。该分析基于BGN密码系统使用配对e:G×G→G_T这一事实,而配对的存在导致群G上的DDH问题可解。我们还提出了如何防止Shi等人盲化技术用于BGN密码系统时出现此类隐私泄露的方法。