{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:01:09Z","timestamp":1777806069376,"version":"3.51.4"},"reference-count":95,"publisher":"SAGE Publications","issue":"1","license":[{"start":{"date-parts":[[2018,10,26]],"date-time":"2018-10-26T00:00:00Z","timestamp":1540512000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2019,1,11]]},"abstract":"<jats:p>Cloud storage has rapidly become a cornerstone of many IT infrastructures, constituting a seamless solution for the backup, synchronization, and sharing of large amounts of data. Putting user data in the direct control of cloud service providers, however, raises security and privacy concerns related to the integrity of outsourced data, the accidental or intentional leakage of sensitive information, the profiling of user activities and so on. Furthermore, even if the cloud provider is trusted, users having access to outsourced files might be malicious and misbehave. These concerns are particularly serious in sensitive applications like personal health records and credit score systems.<\/jats:p>\n                  <jats:p>To tackle this problem, we present [Formula: see text], a definitional framework for Group Oblivious RAM, in which we formalize several security and privacy properties such as secrecy, integrity, anonymity, and obliviousness. [Formula: see text] allows per entry access control, as selected by the data owner. [Formula: see text] is the first framework to define such a wide range of security and privacy properties for outsourced storage. Regarding obliviousness, we tackle two different attacker models: our first definition protects against an honest-but-curious server while our second definition protects against such a server colluding with malicious clients.<\/jats:p>\n                  <jats:p>In the latter model, we prove a server-side computational lower bound of [Formula: see text] where n is the number of entries in the database, i.e., every operations requires to process a constant fraction of the database. Furthermore, we present two constructions: a pure cryptographic instantiation, which achieves an [Formula: see text] amortized communication and computation complexity and a construction based on a trusted proxy with logarithmic communication and server-side computational complexity. The second construction bypasses the previously established lower bound leveraging a trusted party. Both schemes achieve secrecy, integrity, and obliviousness with respect to a server colluding with malicious clients, but not anonymity due to the deployed access control mechanism.<\/jats:p>\n                  <jats:p>In the former model, we present a cryptographic system that achieves secrecy, integrity, obliviousness, and anonymity. In the process of designing an efficient construction, we developed three new, generally applicable cryptographic schemes, namely, batched zero-knowledge proof of shuffle correctness, the hash-and-proof paradigm, which even improves upon the former, and an accountability technique based on chameleon signatures, which we consider of independent interest.<\/jats:p>\n                  <jats:p>We implemented our constructions in Amazon Elastic Compute Cloud (EC2) and ran a performance evaluation demonstrating the scalability and efficiency of our construction.<\/jats:p>","DOI":"10.3233\/jcs-171030","type":"journal-article","created":{"date-parts":[[2018,10,26]],"date-time":"2018-10-26T12:38:39Z","timestamp":1540557519000},"page":"1-47","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":1,"title":["Group ORAM for privacy and access control in outsourced personal records"],"prefix":"10.1177","volume":"27","author":[{"given":"Matteo","family":"Maffei","sequence":"first","affiliation":[{"name":"TU Wien, Favoritenstra\u00dfe 9-11, Stiege 2, 1040 Wien, Austria. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giulio","family":"Malavolta","sequence":"additional","affiliation":[{"name":"Nuremberg Campus of Technology, F\u00fcrther Str 246c, Eingang 5, 2. OG, room 11.2.23, 90429 N\u00fcrnberg, Germany. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manuel","family":"Reinert","sequence":"additional","affiliation":[{"name":"Saarland University, Saarland Informatics Campus E9.1, 66041 Saarbr\u00fccken, Germany. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dominique","family":"Schr\u00f6der","sequence":"additional","affiliation":[{"name":"Nuremberg Campus of Technology, F\u00fcrther Str 246c, Eingang 5, 2. OG, room 11.2.23, 90429 N\u00fcrnberg, Germany. E-mails:\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2018,10,26]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"C.Aguilar-Melchor, J.Barrier, L.Fousse and M.O.Killijian, XPIR: Private information retrieval for everyone, in: PETS\u201916, De Gruyter, 2016, pp. 155\u2013174.","DOI":"10.1515\/popets-2016-0010"},{"key":"ref002","doi-asserted-by":"crossref","unstructured":"M.Ajtai, Oblivious RAMs without cryptographic assumptions, in: STOC\u201910, ACM, 2010, pp. 181\u2013190. doi:10.1145\/1806689.1806716.","DOI":"10.1145\/1806689.1806716"},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"I.E.Akkus, R.Chen, M.Hardt, P.Francis and J.Gehrke, Non-tracking Web analytics, in: CCS\u201912, ACM, 2012, pp. 687\u2013698.","DOI":"10.1145\/2382196.2382268"},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"D.Apon, J.Katz, E.Shi and A.Thiruvengadam, Verifiable oblivious storage, in: PKC\u201914, LNCS, Springer, 2014, pp. 131\u2013148.","DOI":"10.1007\/978-3-642-54631-0_8"},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"G.Ateniese and B.de Medeiros, On the key exposure problem in Chameleon hashes, in: SCN\u201904, LNCS, Springer, 2004, pp. 165\u2013179.","DOI":"10.1007\/978-3-540-30598-9_12"},{"key":"ref006","unstructured":"J.Backes, S.Lorenz and K.Pecina, Zero-knowledge Library, online at github.com\/peloba\/zk-library."},{"key":"ref007","doi-asserted-by":"crossref","unstructured":"M.Backes, S.Lorenz, M.Maffei and K.Pecina, Anonymous Webs of trust, in: PETS\u201910, LNCS, Springer, 2010, pp. 130\u2013148.","DOI":"10.1007\/978-3-642-14527-8_8"},{"key":"ref008","unstructured":"M.Backes, M.Maffei and K.Pecina, Automated synthesis of privacy-preserving distributed applications, in: NDSS\u201912, Internet Society, 2012."},{"key":"ref009","doi-asserted-by":"crossref","unstructured":"F.Baldimtsi and A.Lysyanskaya, Anonymous credentials light, in: CCS\u201913, ACM, 2013, pp. 1087\u20131098. doi:10.1145\/2508859.2516687.","DOI":"10.1145\/2508859.2516687"},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"S.Bayer and J.Groth, Efficient zero-knowledge argument for correctness of a shuffle, in: EUROCRYPT\u201912, LNCS, Springer, 2012, pp. 263\u2013280.","DOI":"10.1007\/978-3-642-29011-4_17"},{"key":"ref011","doi-asserted-by":"crossref","unstructured":"M.Bellare, A.Desai, D.Pointcheval and P.Rogaway, Relations among notions of security for public-key encryption schemes, in: CRYPTO\u201998, LNCS, Springer, 1998, pp. 26\u201345.","DOI":"10.1007\/BFb0055718"},{"key":"ref012","doi-asserted-by":"crossref","unstructured":"S.Benabbas, R.Gennaro and Y.Vahlis, Verifiable delegation of computation over large datasets, in: CRYPTO\u201911, LNCS, Springer, 2011, pp. 111\u2013131.","DOI":"10.1007\/978-3-642-22792-9_7"},{"key":"ref013","doi-asserted-by":"crossref","unstructured":"V.Bindschaedler, M.Naveed, X.Pan, X.Wang and Y.Huang, Practicing oblivious access on cloud storage: The gap, the fallacy, and the new way forward, in: CCS\u201915, ACM, 2015, pp. 837\u2013849. doi:10.1145\/2810103.2813649.","DOI":"10.1145\/2810103.2813649"},{"key":"ref014","unstructured":"BlueKrypt, Cryptograhpic Key Length Recommendation, online at www.keylength.com."},{"key":"ref015","doi-asserted-by":"crossref","unstructured":"E.Boyle, K.M.Chung and R.Pass, Oblivious parallel RAM and applications, in: TCC\u201916, LNCS, Springer, 2016.","DOI":"10.1007\/978-3-662-49099-0_7"},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"J.Camenisch, M.Kohlweiss and C.Soriente, An accumulator based on bilinear maps and efficient revocation for anonymous credentials, in: PKC\u201909, LNCS, Springer, 2009, pp. 481\u2013500.","DOI":"10.1007\/978-3-642-00468-1_27"},{"key":"ref017","doi-asserted-by":"crossref","unstructured":"B.Carbunar and R.Sion, Regulatory compliant oblivious RAM, in: ACNS\u201910, LNCS, Springer, 2010, pp. 456\u2013474.","DOI":"10.1007\/978-3-642-13708-2_27"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"I.Carri\u00f3n Se\u00f1or, L.J.Fern\u00e1ndez-Alem\u00e1n and A.Toval, Are personal health records safe? A review of free Web-accessible personal health record privacy policies, J. Med. Int. Res. 14(4) (2012), e114.","DOI":"10.2196\/jmir.1904"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"J.L.Carter and M.N.Wegman, Universal classes of hash functions (extended abstract), in: STOC\u201977, ACM, 1977, pp. 106\u2013112. doi:10.1145\/800105.803400.","DOI":"10.1145\/800105.803400"},{"key":"ref020","doi-asserted-by":"crossref","unstructured":"D.Chaum, C.Cr\u00e9peau and I.Damgard, Multiparty unconditionally secure protocols, in: STOC\u201988, ACM, 1988, pp. 11\u201319. doi:10.1145\/62212.62214.","DOI":"10.1145\/62212.62214"},{"key":"ref021","doi-asserted-by":"publisher","DOI":"10.1145\/358549.358563"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"B.Chen, H.Lin and S.Tessaro, Oblivious parallel RAM: Improved efficiency and generic constructions, in: TCC\u201916, LNCS., Springer, 2016.","DOI":"10.1007\/978-3-662-49099-0_8"},{"key":"ref023","doi-asserted-by":"crossref","unstructured":"R.Chen, I.Ekin Akkus and P.Francis, SplitX: High-performance private analytics, in: SIGCOMM\u201913, ACM, 2013, pp. 315\u2013326. doi:10.1145\/2486001.2486013.","DOI":"10.1145\/2486001.2486013"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1145\/293347.293350"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"R.Cramer, I.Damg\u00e5rd and B.Schoenmakers, Proofs of partial knowledge and simplified design of witness hiding protocols, in: CRYPTO\u201994, LNCS, Springer, 1994, pp. 174\u2013187.","DOI":"10.1007\/3-540-48658-5_19"},{"key":"ref026","doi-asserted-by":"crossref","unstructured":"R.Cramer, R.Gennaro and B.Schoenmakers, A secure and optimally efficient multi-authority election scheme, in: EUROCRYPT\u201997, LNCS, Springer, 1997, pp. 103\u2013118.","DOI":"10.1007\/3-540-69053-0_9"},{"key":"ref027","doi-asserted-by":"crossref","unstructured":"R.Cramer and V.Shoup, A practical public key cryptosystem provably secure against adaptive chosen ciphertext attack, in: CRYPTO\u201998, LNCS, Springer, 1998, pp. 13\u201325.","DOI":"10.1007\/BFb0055717"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"C.Culnane and S.Schneider, A peered bulletin board for robust use in verifiable voting systems, in: CSF\u201914, IEEE Press, 2014, pp. 169\u2013183.","DOI":"10.1109\/CSF.2014.20"},{"key":"ref029","doi-asserted-by":"crossref","unstructured":"J.Daemen and V.Rijmen, The Design of Rijndael, AES \u2013 the Advanced Encryption Standard, Springer, 2002.","DOI":"10.1007\/978-3-662-04722-4_1"},{"key":"ref030","doi-asserted-by":"crossref","unstructured":"D.Daglish and N.Archer, Electronic Personal Health Record Systems: A Brief Review of Privacy, Security, and Architectural Issues,\n                      World Congress on Privacy, Security, Trust and the Management of e-Business\n                      (2009), 110\u2013120. doi:10.1109\/CONGRESS.2009.14.","DOI":"10.1109\/CONGRESS.2009.14"},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"I.Damg\u00e5rd, S.Meldgaard and J.B.Nielsen, Perfectly secure oblivious RAM without random oracles, in: TCC\u201911, LNCS, Springer, 2011, pp. 144\u2013163.","DOI":"10.1007\/978-3-642-19571-6_10"},{"key":"ref032","unstructured":"J.Dautrich, E.Stefanov and E.Shi, Burst ORAM: Minimizing ORAM response times for bursty access patterns, in: USENIX\u201914, USENIX Association, 2014, pp. 749\u2013764."},{"key":"ref033","doi-asserted-by":"crossref","unstructured":"S.De Capitani di Vimercati, S.Foresti, S.Jajodia, S.Paraboschi and P.Samarati, Private data indexes for selective access to outsourced data, in: WPES\u201911, ACM, 2011, pp. 69\u201380.","DOI":"10.1145\/2046556.2046566"},{"key":"ref034","first-page":"1","author":"De Capitani di Vimercati S.","year":"2018","journal-title":"Journal of Computer Security"},{"key":"ref035","unstructured":"A.De Caro, jPBC \u2013 Java Library for Pairing Based Cryptography, online at http:\/\/gas.dia.unisa.it\/projects\/jpbc\/."},{"key":"ref036","doi-asserted-by":"crossref","unstructured":"A.Demers, D.Greene, C.Hauser, W.Irish, J.Larson, S.Shenker, H.Sturgis, D.Swinehart and D.Terry, Epidemic algorithms for replicated database maintenance, in: PODC\u201987, ACM, 1987, pp. 1\u201312.","DOI":"10.1145\/41840.41841"},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"R.Dingledine, N.Mathewson and P.Syverson, Tor: The second-generation onion router, in: USENIX\u201904, USENIX Association, 2004, pp. 303\u2013320.","DOI":"10.21236\/ADA465464"},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"C.Dong and L.Chen, A fast single server private information retrieval protocol with low communication cost, in: ESORICS\u201914, LNCS, Vol. 8712, Springer, 2014, pp. 380\u2013399.","DOI":"10.1007\/978-3-319-11203-9_22"},{"key":"ref039","doi-asserted-by":"crossref","unstructured":"T.El Gamal, A public key cryptosystem and a signature scheme based on discrete logarithms, in: CRYPTO\u201984, LNCS, Springer, 1985, pp. 10\u201318.","DOI":"10.1007\/3-540-39568-7_2"},{"key":"ref040","doi-asserted-by":"crossref","unstructured":"C.Erway, A.K\u00fcp\u00e7\u00fc, C.Papamanthou and R.Tamassia, Dynamic provable data possession, in: CCS\u201909, ACM, 2009, pp. 213\u2013222. doi:10.1145\/1653662.1653688.","DOI":"10.1145\/1653662.1653688"},{"key":"ref041","doi-asserted-by":"crossref","unstructured":"A.Fiat and A.Shamir, How to prove yourself: Practical solutions to identification and signature problems, in: CRYPTO\u201986, Springer, 1987, pp. 186\u2013194.","DOI":"10.1007\/3-540-47721-7_12"},{"key":"ref042","doi-asserted-by":"crossref","unstructured":"M.Franz, C.Carbunar, R.Sion, S.Katzenbeisser, M.Sotakova, P.Williams and A.Peter, Oblivious outsourced storage with delegation, in: FC\u201911, Springer, 2011, pp. 127\u2013140.","DOI":"10.1007\/978-3-642-27576-0_11"},{"key":"ref043","doi-asserted-by":"crossref","unstructured":"D.M.Freeman, Converting pairing-based cryptosystems from composite-order groups to prime-order groups, in: EUROCRYPT\u201910, LNCS, Springer, 2010, pp. 44\u201361.","DOI":"10.1007\/978-3-642-13190-5_3"},{"key":"ref044","unstructured":"D.L.Gazzoni Filho and P.S.L.M.Barreto, Demonstrating Data Possession and Uncheatable Data Transfer, Cryptology ePrint Archive, Report 2006\/150, 2006. http:\/\/eprint.iacr.org\/."},{"key":"ref045","doi-asserted-by":"crossref","unstructured":"C.Gentry and B.Waters, Adaptive security in broadcast encryption systems (with short ciphertexts), in: EUROCRYPT\u201909, LNCS, Springer, 2009, pp. 171\u2013188.","DOI":"10.1007\/978-3-642-01001-9_10"},{"key":"ref046","doi-asserted-by":"crossref","unstructured":"O.Goldreich, S.Micali and A.Wigderson, How to play ANY mental game, in: STOC\u201987, ACM, 1987, pp. 218\u2013229. doi:10.1145\/28395.28420.","DOI":"10.1145\/28395.28420"},{"key":"ref047","doi-asserted-by":"publisher","DOI":"10.1145\/233551.233553"},{"key":"ref048","doi-asserted-by":"crossref","unstructured":"S.Goldwasser and S.Micali, Probabilistic encryption & how to play mental poker keeping secret all partial information, in: STOC\u201982, ACM, 1982, pp. 365\u2013377. doi:10.1145\/800070.802212.","DOI":"10.1145\/800070.802212"},{"key":"ref049","doi-asserted-by":"crossref","unstructured":"M.T.Goodrich and M.Mitzenmacher, Privacy-preserving access of outsourced data via oblivious RAM simulation, in: ICALP\u201911, LNCS, Springer, 2011, pp. 576\u2013587.","DOI":"10.1007\/978-3-642-22012-8_46"},{"key":"ref050","doi-asserted-by":"crossref","unstructured":"M.T.Goodrich, M.Mitzenmacher, O.Ohrimenko and R.Tamassia, Privacy-preserving group data access via stateless oblivious RAM simulation, in: SODA\u201912, SIAM, 2012, pp. 157\u2013167.","DOI":"10.1137\/1.9781611973099.14"},{"key":"ref051","doi-asserted-by":"publisher","DOI":"10.1137\/080725386"},{"key":"ref052","doi-asserted-by":"crossref","unstructured":"J.Heather and D.Lundin, The append-only web bulletin board, in: FAST\u201909, Springer, 2009, pp. 242\u2013256.","DOI":"10.1007\/978-3-642-01465-9_16"},{"key":"ref053","doi-asserted-by":"crossref","unstructured":"Y.Huang and I.Goldberg, Outsourced private information retrieval with pricing and access control, in: WPES\u201913, ACM, 2013.","DOI":"10.1145\/2517840.2517854"},{"key":"ref054","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.49"},{"key":"ref055","unstructured":"M.Islam, M.Kuzu and M.Kantarcioglu, Access pattern disclosure on searchable encryption: Ramification, attack and mitigation, in: NDSS\u201912, Internet Society, 2012."},{"key":"ref056","unstructured":"M.Jakobsson and A.Juels, Millimix: Mixing in Small Batches, Technical Report 99-33, DIMACS, 1999."},{"key":"ref057","unstructured":"M.Jakobsson, A.Juels and R.L.Rivest, Making mix nets robust for electronic voting by randomized partial checking, in: USENIX\u201902, USENIX Association, 2002, pp. 339\u2013353."},{"key":"ref058","doi-asserted-by":"crossref","unstructured":"J.Katz, A.Sahai and B.Waters, Predicate encryption supporting disjunctions, polynomial equations, and inner products, in: EUROCRYPT\u201908, Springer, 2008, pp. 146\u2013162.","DOI":"10.1007\/978-3-540-78967-3_9"},{"key":"ref059","doi-asserted-by":"crossref","unstructured":"B.H,Kim and D.Lie, Caelus: Verifying the consistency of cloud services with battery-powered devices, in: S&P\u201915, IEEE Press, 2015, pp. 880\u2013896.","DOI":"10.1109\/SP.2015.59"},{"key":"ref060","unstructured":"P.Korde, V.Panwar and S.Kalse, Securing Personal Health Records in Cloud using Attribute Based Encryption,\n                      Int. J. Eng. Adv. Tech.\n                      (2013)."},{"key":"ref061","doi-asserted-by":"crossref","unstructured":"R.K\u00fcsters, T.Truderung and A.Vogt, Accountability: Definition and relationship to verifiability, in: CCS\u201910, ACM, 2010, pp. 526\u2013535. doi:10.1145\/1866307.1866366.","DOI":"10.1145\/1866307.1866366"},{"key":"ref062","doi-asserted-by":"crossref","unstructured":"M.Li, S.Yu, K.Ren and W.Lou, Securing personal health records in cloud computing: Patient-centric and fine-grained data access control in multi-owner settings, in: SECURECOMM\u201910, 2010.","DOI":"10.1007\/978-3-642-16161-2_6"},{"key":"ref063","doi-asserted-by":"crossref","unstructured":"Y.Lindell and B.Pinkas, An efficient protocol for secure two-party computation in the presence of malicious adversaries, in: EUROCRYPT\u201907, LNCS, Springer, 2007, pp. 52\u201378.","DOI":"10.1007\/978-3-540-72540-4_4"},{"key":"ref064","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-008-9036-8"},{"key":"ref065","doi-asserted-by":"crossref","unstructured":"H.L\u00f6hr, A.R.Sadeghi and M.Winandy, Securing the e-health cloud, in: IHI\u201910, ACM, 2010, pp. 220\u2013229. doi:10.1145\/1882992.1883024.","DOI":"10.1145\/1882992.1883024"},{"key":"ref066","unstructured":"J.R.Lorch, B.Parno, J.Mickens, M.Raykova and J.Schiffman, Shroud: Ensuring private access to large-scale data in the data center, in: FAST\u201913, USENIX Association, 2013, pp. 199\u2013214."},{"key":"ref067","unstructured":"B.Lynn, PBC \u2013 C Library for Pairing Based Cryptography, online at http:\/\/crypto.stanford.edu\/pbc\/."},{"key":"ref068","doi-asserted-by":"crossref","unstructured":"M.Maas, E.Love, E.Stefanov, M.Tiwari, E.Shi, K.Asanovic, J.Kubiatowicz and D.Song, PHANTOM: Practical oblivious computation in a secure processor, in: CCS\u201913, ACM, 2013, pp. 311\u2013324. doi:10.1145\/2508859.2516692.","DOI":"10.1145\/2508859.2516692"},{"key":"ref069","unstructured":"M.Maffei, G.Malavolta, M.Reinert and D.S.Schr\u00f6der, GORAM: Privacy, Access Control, and Verifiability in Group Outsourced Storage, 2014, Full version online at http:\/\/www.sps.cs.uni-saarland.de\/publications\/goram.pdf."},{"key":"ref070","doi-asserted-by":"crossref","unstructured":"M.Maffei, K.Pecina and M.Reinert, Security and privacy by declarative design, in: CSF\u201913, IEEE Press, 2013, pp. 81\u201396.","DOI":"10.1109\/CSF.2013.13"},{"key":"ref071","doi-asserted-by":"crossref","unstructured":"T.Mayberry, E.O.Blass and A.H.Chan, Efficient private file retrieval by combining ORAM and PIR, in: NDSS\u201914, Internet Society, 2013.","DOI":"10.14722\/ndss.2014.23033"},{"key":"ref072","doi-asserted-by":"crossref","unstructured":"A.Miyaji, M.Nakabayashi and S.Takano, Characterization of elliptic curve traces under FR-reduction, in: ICISC\u201900, LNCS, Vol. 2015, Springer, 2001, pp. 90\u2013108.","DOI":"10.1007\/3-540-45247-8_8"},{"key":"ref073","unstructured":"R.Ostrovsky and W.E.SkeithIII, Algebraic Lower Bounds for Computing on Encrypted Data,\n                      ECCC\n                      14\n                      (022) (2007)."},{"key":"ref074","doi-asserted-by":"crossref","unstructured":"P.Paillier, Public-key cryptosystems based on composite degree residuosity classes, in: EUROCRYPT\u201999, LNCS, Springer, 1999, pp. 223\u2013238.","DOI":"10.1007\/3-540-48910-X_16"},{"key":"ref075","doi-asserted-by":"crossref","unstructured":"C.Papamanthou, E.Shi, R.Tamassia and K.Yi, Streaming authenticated data structures, in: EUROCRYPT\u201913, 2013.","DOI":"10.1007\/978-3-642-38348-9_22"},{"key":"ref076","doi-asserted-by":"crossref","unstructured":"B.Pinkas and T.Reinman, Oblivious RAM revisited, in: CRYPTO\u201910, LNCS, Springer, 2010, pp. 502\u2013519.","DOI":"10.1007\/978-3-642-14623-7_27"},{"key":"ref077","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"ref078","doi-asserted-by":"crossref","unstructured":"D.S.Roche, A.Aviv and S.G.Choi, A practical oblivious map data structure with secure deletion and history independence, in: S&P\u201916, IEEE Press, 2016.","DOI":"10.1109\/SP.2016.19"},{"key":"ref079","doi-asserted-by":"crossref","unstructured":"C.Sahin, V.Zakhary, A.El Abbadi, H.R.Lin and S.Tessaro, TaoStore: Overcoming asynchronicity in oblivious data storage, in: S&P\u201916, IEEE Press, 2016.","DOI":"10.1109\/SP.2016.20"},{"key":"ref080","doi-asserted-by":"crossref","unstructured":"C.P.Schnorr, Efficient identification and signatures for smart cards, in: CRYPTO\u201989, LNCS, Springer, 1989, pp. 239\u2013252.","DOI":"10.1007\/0-387-34805-0_22"},{"key":"ref081","doi-asserted-by":"crossref","unstructured":"D.Schr\u00f6der and H.Schr\u00f6der, Verifiable data streaming, in: CCS\u201912, ACM, 2012, pp. 953\u2013964. doi:10.1145\/2382196.2382297.","DOI":"10.1145\/2382196.2382297"},{"key":"ref082","doi-asserted-by":"crossref","unstructured":"D.Schr\u00f6der and M.Simkin, VeriStream \u2013 a framework for verifiable data streaming, in: FC\u201915, Springer, 2015.","DOI":"10.1007\/978-3-662-47854-7_34"},{"key":"ref083","unstructured":"T.Schwarz and E.L.Miller, Store, Forget, and Check: Using Algebraic Signatures to Check Remotely Administered Storage, 2006."},{"key":"ref084","doi-asserted-by":"crossref","unstructured":"H.Shacham and B.Waters, Compact proofs of retrievability, in: ASIACRYPT\u201908, LNCS, Springer, 2008, pp. 90\u2013107.","DOI":"10.1007\/978-3-540-89255-7_7"},{"key":"ref085","doi-asserted-by":"crossref","unstructured":"E.Shi, T.H.H.Chan, E.Stefanov and M.Li, Oblivious RAM with\n                      O\n                      ((log\n                      n\n                      )\n                      3\n                      ) worst-case cost, in: ASIACRYPT\u201911, LNCS, Springer, 2011, pp. 197\u2013214.","DOI":"10.1007\/978-3-642-25385-0_11"},{"key":"ref086","doi-asserted-by":"crossref","unstructured":"E.Stefanov and E.Shi, Multi-cloud oblivious storage, in: CCS\u201913, ACM, 2013, pp. 247\u2013258. doi:10.1145\/2508859.2516673.","DOI":"10.1145\/2508859.2516673"},{"key":"ref087","doi-asserted-by":"crossref","unstructured":"E.Stefanov and E.Shi, ObliviStore: High performance oblivious cloud storage, in: S&P\u201913, IEEE Press, 2013, pp. 253\u2013267.","DOI":"10.1109\/SP.2013.25"},{"key":"ref088","unstructured":"E.Stefanov, E.Shi and D.Song, Towards practical oblivious RAM, in: NDSS\u201912, Internet Society, 2012."},{"key":"ref089","doi-asserted-by":"crossref","unstructured":"E.Stefanov, M.van Dijk, A.Oprea and A.Juels, Iris: A Scalable Cloud File System with Efficient Integrity Checks, Cryptology ePrint Archive, Report 2011\/585, 2011. http:\/\/eprint.iacr.org\/.","DOI":"10.1145\/2420950.2420985"},{"key":"ref090","doi-asserted-by":"crossref","unstructured":"E.Stefanov, M.van Dijk, E.Shi, C.Fletcher, L.Ren, X.Yu and S.Devadas, Path ORAM: An extremely simple oblivious RAM protocol, in: CCS\u201913, ACM, 2013.","DOI":"10.1145\/2508859.2516660"},{"key":"ref091","doi-asserted-by":"crossref","unstructured":"M.van Dijk, A.Juels, A.Oprea, R.L.Rivest, E.Stefanov and N.Triandopoulos, Hourglass schemes: How to prove that cloud files are encrypted, in: CCS\u201912, ACM, 2012, pp. 265\u2013280.","DOI":"10.1145\/2382196.2382227"},{"key":"ref092","doi-asserted-by":"crossref","unstructured":"P.Williams, R.Sion and B.Carbunar, Building castles out of mud: Practical access pattern privacy and correctness on untrusted storage, in: CCS\u201908, ACM, 2008, pp. 139\u2013148. doi:10.1145\/1455770.1455790.","DOI":"10.1145\/1455770.1455790"},{"key":"ref093","doi-asserted-by":"crossref","unstructured":"P.Williams, R.Sion and A.Tomescu, PrivateFS: A parallel oblivious file system, in: CCS\u201912, ACM, 2012, pp. 977\u2013988. doi:10.1145\/2382196.2382299.","DOI":"10.1145\/2382196.2382299"},{"key":"ref094","doi-asserted-by":"publisher","DOI":"10.1007\/s10916-006-9019-y"},{"key":"ref095","doi-asserted-by":"crossref","unstructured":"A.C.C.Yao, How to generate and exchange secrets, in: FOCS\u201986, IEEE Press, 1986, pp. 162\u2013167.","DOI":"10.1109\/SFCS.1986.25"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-171030","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-171030","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-171030","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:15Z","timestamp":1777495515000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-171030"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,26]]},"references-count":95,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,1,11]]}},"alternative-id":["10.3233\/JCS-171030"],"URL":"https:\/\/doi.org\/10.3233\/jcs-171030","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,10,26]]}}}