{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T10:42:40Z","timestamp":1756464160941,"version":"3.37.3"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T00:00:00Z","timestamp":1688428800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T00:00:00Z","timestamp":1688428800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Publish\/subscribe(pub\/sub) systems are widely used in large-scale messaging systems due to their asynchronous and decoupled nature. With the population of pub\/sub cloud services, the privacy protection problem of pub\/sub systems has started to emerge, and events and subscriptions are exposed when executing event matching on untrustworthy cloud brokers. However, as the number of subscriptions increases, the effectiveness of the previous confidentiality protection approaches declines drastically. In this paper, we propose SBM (scalable blind matching), an effective confidentiality protection scheme for pub\/sub systems. To the best of our knowledge, SBM is the first scheme that applies order-preserving encryption algorithm to protect the system\u2019s confidentiality and ensure its scalability. In this scheme, SBM-I is highly effective in subscription matching but is unable to achieve ideal security IND-OCPA, whereas SBM-II is suggested to ensure system security and SGX is used to reduce interaction and boost ciphertext matching performance. The experiment demonstrates that this method has better matching performance compared to others: the average matching time of SBM-I is 3\u20134 orders of magnitude faster than the matching algorithm MP and SGX-based algorithm SCBR when the number of subscriptions is 500,000, and the average matching time of SBM-II is 40 times faster than MP and 24 times than SCBR.<\/jats:p>","DOI":"10.1186\/s42400-023-00165-w","type":"journal-article","created":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T02:01:37Z","timestamp":1688436097000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["An efficient confidentiality protection solution for pub\/sub system"],"prefix":"10.1186","volume":"6","author":[{"given":"Jinglei","family":"Pei","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuyang","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingling","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2490-6934","authenticated-orcid":false,"given":"Ruisheng","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lina","family":"Lan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shui","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinqiao","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhaofeng","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,7,4]]},"reference":[{"key":"165_CR1","doi-asserted-by":"crossref","unstructured":"Agrawal R, Kiernan J, Srikant R, Xu Y (2004) Order preserving encryption for numeric data. In: Proceedings of the 2004 ACM SIGMOD international conference on management of data, pp 563\u2013574","DOI":"10.1145\/1007568.1007632"},{"key":"165_CR2","unstructured":"Amazon (2022) Pub\/Sub messaging. https:\/\/aws.amazon.com\/pub-sub-messaging"},{"key":"165_CR3","doi-asserted-by":"crossref","unstructured":"Arnautov S, Brito A, Felber P, Fetzer C, Gregor F, Krahn R, Ozga W, Martin A, Schiavoni V, Silva F et al (2018) Pubsub-sgx: exploiting trusted execution environments for privacy-preserving publish\/subscribe systems. In: 2018 IEEE 37th symposium on reliable distributed systems (SRDS), pp 123\u2013132. IEEE","DOI":"10.1109\/SRDS.2018.00023"},{"issue":"3","key":"165_CR4","first-page":"308","volume":"14","author":"R Barazzutti","year":"2015","unstructured":"Barazzutti R, Felber P, Mercier H, Onica E, Riviere E (2015) Efficient and confidentiality-preserving content-based publish\/subscribe with prefiltering. IEEE Trans Dependable Secure Comput 14(3):308\u2013325","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"165_CR5","doi-asserted-by":"crossref","unstructured":"Bethencourt J, Sahai A, Waters B (2007) Ciphertext-policy attribute-based encryption. In: 2007 IEEE symposium on security and privacy (SP\u201907), pp 321\u2013334 . IEEE","DOI":"10.1109\/SP.2007.11"},{"issue":"7","key":"165_CR6","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1145\/362686.362692","volume":"13","author":"BH Bloom","year":"1970","unstructured":"Bloom BH (1970) Space\/time trade-offs in hash coding with allowable errors. Commun ACM 13(7):422\u2013426","journal-title":"Commun ACM"},{"key":"165_CR7","doi-asserted-by":"crossref","unstructured":"Boldyreva A, Chenette N, Lee Y, O\u2019neill A (2009) Order-preserving symmetric encryption. In: Annual international conference on the theory and applications of cryptographic techniques, pp 224\u2013241. Springer","DOI":"10.1007\/978-3-642-01001-9_13"},{"key":"165_CR8","doi-asserted-by":"crossref","unstructured":"Boldyreva A, Chenette N, O\u2019Neill A (2011) Order-preserving encryption revisited: improved security analysis and alternative solutions. In: Annual cryptology conference, pp 578\u2013595 (2011). Springer","DOI":"10.1007\/978-3-642-22792-9_33"},{"key":"165_CR9","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1016\/j.future.2016.10.013","volume":"71","author":"C Borcea","year":"2017","unstructured":"Borcea C, Polyakov Y, Rohloff K, Ryan G et al (2017) Picador: end-to-end encrypted publish-subscribe information distribution with proxy re-encryption. Future Gener Comput Syst 71:177\u2013191","journal-title":"Future Gener Comput Syst"},{"issue":"3","key":"165_CR10","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1145\/380749.380767","volume":"19","author":"A Carzaniga","year":"2001","unstructured":"Carzaniga A, Rosenblum DS, Wolf AL (2001) Design and evaluation of a wide-area event notification service. ACM Trans Comput Syst (TOCS) 19(3):332\u2013383","journal-title":"ACM Trans Comput Syst (TOCS)"},{"key":"165_CR11","doi-asserted-by":"crossref","unstructured":"Choi S, Ghinita G, Bertino E (2010) A privacy-enhancing content-based publish\/subscribe system using scalar product preserving transformations. In: International conference on database and expert systems applications, pp 368\u2013384. Springer, Berlin","DOI":"10.1007\/978-3-642-15364-8_32"},{"key":"165_CR12","doi-asserted-by":"crossref","unstructured":"Ding T, Qian S, Cao J, Xue G, Li M (2020) Scsl: optimizing matching algorithms to improve real-time for content-based pub\/sub systems. In: 2020 IEEE international parallel and distributed processing symposium (IPDPS), pp 148\u2013157. IEEE","DOI":"10.1109\/IPDPS47924.2020.00025"},{"issue":"3","key":"165_CR13","doi-asserted-by":"publisher","first-page":"367","DOI":"10.3233\/JCS-2010-0415","volume":"19","author":"C Dong","year":"2011","unstructured":"Dong C, Russello G, Dulay N (2011) Shared and searchable encrypted data for untrusted servers. J Comput Secur 19(3):367\u2013397","journal-title":"J Comput Secur"},{"issue":"2","key":"165_CR14","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1145\/857076.857078","volume":"35","author":"PT Eugster","year":"2003","unstructured":"Eugster PT, Felber PA, Guerraoui R, Kermarrec A-M (2003) The many faces of publish\/subscribe. ACM Comput Surv (CSUR) 35(2):114\u2013131","journal-title":"ACM Comput Surv (CSUR)"},{"key":"165_CR15","doi-asserted-by":"crossref","unstructured":"Gaballah SA, Coijanovic C, Strufe T, M\u00fchlh\u00e4user M (2021) 2PPS\u2014publish\/subscribe with provable privacy. In: 2021 40th international symposium on reliable distributed systems (SRDS), pp 198\u2013209. IEEE","DOI":"10.1109\/SRDS53918.2021.00028"},{"key":"165_CR16","unstructured":"Google (2022) Pubsub. https:\/\/cloud.google.com\/pubsub\/docs\/overview"},{"key":"165_CR17","first-page":"182","volume":"5","author":"J Guo","year":"2018","unstructured":"Guo J, Miao M, Wang J (2018) Research and progress of order preserving encryption. J Cryptol Res 5:182\u2013195","journal-title":"J Cryptol Res"},{"issue":"7","key":"165_CR18","doi-asserted-by":"publisher","first-page":"2014","DOI":"10.1016\/j.comnet.2012.02.013","volume":"56","author":"M Ion","year":"2012","unstructured":"Ion M, Russello G, Crispo B (2012) Design and implementation of a confidentiality and access control solution for publish\/subscribe systems. Comput Netw 56(7):2014\u20132037","journal-title":"Comput Netw"},{"issue":"3","key":"165_CR19","doi-asserted-by":"publisher","first-page":"251","DOI":"10.14778\/3291264.3291270","volume":"12","author":"S Ji","year":"2018","unstructured":"Ji S, Jacobsen H-A (2018) Ps-tree-based efficient Boolean expression matching for high-dimensional and dense workloads. Proc VLDB Endow 12(3):251\u2013264","journal-title":"Proc VLDB Endow"},{"key":"165_CR20","unstructured":"Kumar S, Hu Y, Andersen MP, Popa RA, Culler DE (2019) {JEDI}: {Many-to-Many} {End-to-End} encryption and key delegation for {IoT}. In: 28th USENIX security symposium (USENIX Security 19), pp 1519\u20131536"},{"key":"165_CR21","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1016\/j.jpdc.2019.08.011","volume":"135","author":"J Liang","year":"2020","unstructured":"Liang J, Qin Z, Xiao S, Zhang J, Yin H, Li K (2020) Privacy-preserving range query over multi-source electronic health records in public clouds. J Parallel Distrib Comput 135:127\u2013139","journal-title":"J Parallel Distrib Comput"},{"key":"165_CR22","unstructured":"Microsoft (2022) Publisher-subscriber pattern. https:\/\/learn.microsoft.com\/zh-cn\/azure\/architecture\/patterns\/publisher-subscriber"},{"key":"165_CR23","doi-asserted-by":"crossref","unstructured":"Nabeel M, Appel S, Bertino E, Buchmann A (2013) Privacy preserving context aware publish subscribe systems. In: International conference on network and system security, pp 465\u2013478. Springer, Berlin","DOI":"10.1007\/978-3-642-38631-2_34"},{"key":"165_CR24","doi-asserted-by":"crossref","unstructured":"Paillier P (1999) Public-key cryptosystems based on composite degree residuosity classes. In: International conference on the theory and applications of cryptographic techniques, pp 223\u2013238. Springer","DOI":"10.1007\/3-540-48910-X_16"},{"key":"165_CR25","doi-asserted-by":"crossref","unstructured":"Pal P, Lauer G, Khoury J, Hoff N, Loyall J (2012) P3s: a privacy preserving publish-subscribe middleware. In: ACM\/IFIP\/USENIX international conference on distributed systems platforms and open distributed processing, pp 476\u2013495. Springer, Berlin","DOI":"10.1007\/978-3-642-35170-9_24"},{"key":"165_CR26","doi-asserted-by":"crossref","unstructured":"Pires R, Pasin M, Felber P, Fetzer C (2016) Secure content-based routing using intel software guard extensions. In: Proceedings of the 17th international middleware conference, pp 1\u201310","DOI":"10.1145\/2988336.2988346"},{"key":"165_CR27","doi-asserted-by":"crossref","unstructured":"Popa RA, Li FH, Zeldovich N (2013) An ideal-security protocol for order-preserving encoding. In: 2013 IEEE symposium on security and privacy, pp 463\u2013477. IEEE","DOI":"10.1109\/SP.2013.38"},{"issue":"6","key":"165_CR28","doi-asserted-by":"publisher","first-page":"1622","DOI":"10.1109\/TPDS.2014.2323262","volume":"26","author":"S Qian","year":"2014","unstructured":"Qian S, Cao J, Zhu Y, Li M, Wang J (2014) H-tree: an efficient index structure for event matching in content-based publish\/subscribe systems. IEEE Trans Parallel Distrib Syst 26(6):1622\u20131632","journal-title":"IEEE Trans Parallel Distrib Syst"},{"key":"165_CR29","doi-asserted-by":"crossref","unstructured":"Qian S, Cao J, Zhu Y, Li M (2014) Rein: a fast event matching approach for content-based publish\/subscribe systems. In: IEEE INFOCOM 2014-IEEE conference on computer communications, pp 2058\u20132066. IEEE","DOI":"10.1109\/INFOCOM.2014.6848147"},{"key":"165_CR30","doi-asserted-by":"crossref","unstructured":"Raiciu C, Rosenblum DS (2006) Enabling confidentiality in content-based publish\/subscribe infrastructures. In: 2006 securecomm and workshops, pp 1\u201311. IEEE","DOI":"10.1109\/SECCOMW.2006.359552"},{"key":"165_CR31","doi-asserted-by":"crossref","unstructured":"Shikfa A, \u00d6nen M, Molva R (2009) Privacy-preserving content-based publish\/subscribe networks. In: IFIP international information security conference, pp 270\u2013282. Springer, Berlin","DOI":"10.1007\/978-3-642-01244-0_24"},{"issue":"2","key":"165_CR32","doi-asserted-by":"publisher","first-page":"518","DOI":"10.1109\/TPDS.2013.256","volume":"25","author":"MA Tariq","year":"2013","unstructured":"Tariq MA, Koldehofe B, Rothermel K (2013) Securing broker-less publish\/subscribe systems using identity-based encryption. IEEE Trans Parallel Distrib Syst 25(2):518\u2013528","journal-title":"IEEE Trans Parallel Distrib Syst"},{"key":"165_CR33","unstructured":"Wang C, Carzaniga A, Evans D, Wolf AL (2002) Security issues and requirements for internet-scale publish-subscribe systems. In: Proceedings of the 35th annual hawaii international conference on system sciences, pp 3940\u20133947. IEEE"},{"key":"165_CR34","doi-asserted-by":"crossref","unstructured":"Wang S, Pan D, Feng R, Zhang Y (2021) Magikcube: securing cross-domain publish\/subscribe systems with enclave. In: 2021 IEEE 20th international conference on trust, security and privacy in computing and communications (TrustCom), pp 147\u2013154. IEEE","DOI":"10.1109\/TrustCom53373.2021.00037"},{"key":"165_CR35","doi-asserted-by":"crossref","unstructured":"Wong WK, Cheung DW-l, Kao B, Mamoulis N (2009) Secure kNN computation on encrypted databases. In: Proceedings of the 2009 ACM SIGMOD international conference on management of data, pp 139\u2013152","DOI":"10.1145\/1559845.1559862"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00165-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00165-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00165-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T02:03:51Z","timestamp":1688436231000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00165-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,4]]},"references-count":35,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["165"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00165-w","relation":{},"ISSN":["2523-3246"],"issn-type":[{"type":"electronic","value":"2523-3246"}],"subject":[],"published":{"date-parts":[[2023,7,4]]},"assertion":[{"value":"11 March 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 June 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 July 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"34"}}