Abstract:
In cloud computing environments, equality test can effectively address the challenge of comparing whether two ciphertexts are encrypted under the same plaintext without decryption. Among existing schemes, identity-based encryption with equality test (IBEET) significantly simplifies certificate management in traditional public key encryption, demonstrating considerable value. While China's independently developed SM9 encryption algorithm has been successfully selected as an ISO/IEC international standard, existing SM9-based equality test schemes generally remain vulnerable to subversion attacks. Specifically, by subverting the random number generation, an adversary in possession of a backdoor key can recover the plaintext, thereby compromising the security of the scheme. To address this issue, an RCCA(relaxed CCA)-secure identity-based SM9 encryption scheme with equality test (RCCA-SM9-IBEET) were proposed. The scheme deploys cryptographic reverse firewalls (CRF) to re-randomize user inputs and outputs, thereby resisting subversion attacks. Furthermore, we define the concept of OW-ID-RCCA (one-way chosen-ciphertext security against a relaxed chosen identity attack) security model, which supports ciphertext re-randomization for compatibility with the reverse firewalls. A rigorous security proof is provided in the random oracle model. Finally, we analyze the computational and communication costs of the proposed scheme from both theoretical and experimental perspectives.