{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T16:44:33Z","timestamp":1785602673028,"version":"3.56.0"},"reference-count":37,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2023,4,4]],"date-time":"2023-04-04T00:00:00Z","timestamp":1680566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61872204"],"award-info":[{"award-number":["61872204"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["LH2020F050"],"award-info":[{"award-number":["LH2020F050"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["2021-KYYWF-0016"],"award-info":[{"award-number":["2021-KYYWF-0016"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["135309453"],"award-info":[{"award-number":["135309453"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Natural Science Foundation of Heilongjiang Province of China","award":["61872204"],"award-info":[{"award-number":["61872204"]}]},{"name":"Natural Science Foundation of Heilongjiang Province of China","award":["LH2020F050"],"award-info":[{"award-number":["LH2020F050"]}]},{"name":"Natural Science Foundation of Heilongjiang Province of China","award":["2021-KYYWF-0016"],"award-info":[{"award-number":["2021-KYYWF-0016"]}]},{"name":"Natural Science Foundation of Heilongjiang Province of China","award":["135309453"],"award-info":[{"award-number":["135309453"]}]},{"name":"Fundamental Research Funds for Heilongjiang Universities of China","award":["61872204"],"award-info":[{"award-number":["61872204"]}]},{"name":"Fundamental Research Funds for Heilongjiang Universities of China","award":["LH2020F050"],"award-info":[{"award-number":["LH2020F050"]}]},{"name":"Fundamental Research Funds for Heilongjiang Universities of China","award":["2021-KYYWF-0016"],"award-info":[{"award-number":["2021-KYYWF-0016"]}]},{"name":"Fundamental Research Funds for Heilongjiang Universities of China","award":["135309453"],"award-info":[{"award-number":["135309453"]}]},{"name":"Science Research project of Basic scientific research business expenses in Heilongjiang Provincical colleges and universities of China","award":["61872204"],"award-info":[{"award-number":["61872204"]}]},{"name":"Science Research project of Basic scientific research business expenses in Heilongjiang Provincical colleges and universities of China","award":["LH2020F050"],"award-info":[{"award-number":["LH2020F050"]}]},{"name":"Science Research project of Basic scientific research business expenses in Heilongjiang Provincical colleges and universities of China","award":["2021-KYYWF-0016"],"award-info":[{"award-number":["2021-KYYWF-0016"]}]},{"name":"Science Research project of Basic scientific research business expenses in Heilongjiang Provincical colleges and universities of China","award":["135309453"],"award-info":[{"award-number":["135309453"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Devices in the Internet of Things (IoT) usually use cloud storage and cloud computing to save storage and computing cost. Therefore, the efficient realization of one-to-many communication of data on the premise of ensuring the security of cloud storage data is a challenge. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) can not only protect the security of data in the cloud and achieve one-to-many communication but also achieve fine-grained access control for data. However, the single-authority CP-ABE faces the crisis of single point of failure. In order to improve security, the Multi-Authority CP-ABE (MA-CP-ABE) is adopted. Although there are provably-secure MA-CP-ABE schemes, Edward Snowden\u2019s research shows that provably-secure cryptographic schemes are vulnerable to backdoor attacks, resulting in secret disclosure, and thus threatening security. In addition, ABE requires huge computational overhead in key generation, encryption and decryption, which increase with the increase in the number of attributes and the complexity of the access structure, and there are a large number of resource-constrained devices in the IoT. To mitigate this issue, we construct the Online\/Offline MA-CP-ABE with Cryptographic Reverse Firewalls (OO-MA-CP-ABE-CRFs) scheme. This scheme not only uses Cryptographic Reverse Firewall (CRF) to resist backdoor attacks but also uses online\/offline key generation, online\/offline encryption and outsourcing encryption technology to optimize the efficiency of the MA-CP-ABE scheme with reverse firewall, reducing the storage and computing cost of users. Finally, the security of the OO-MA-CP-ABE-CRFs scheme is proved, and the experimental results indicate that the scheme is efficient and practical.<\/jats:p>","DOI":"10.3390\/e25040616","type":"journal-article","created":{"date-parts":[[2023,4,5]],"date-time":"2023-04-05T02:11:41Z","timestamp":1680660701000},"page":"616","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Online\/Offline MA-CP-ABE with Cryptographic Reverse Firewalls for IoT"],"prefix":"10.3390","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2721-2655","authenticated-orcid":false,"given":"Juyan","family":"Li","sequence":"first","affiliation":[{"name":"College of Data Science and Technology, Heilongjiang University, Harbin 150080, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ye","family":"Fan","sequence":"additional","affiliation":[{"name":"College of Data Science and Technology, Heilongjiang University, Harbin 150080, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuefen","family":"Bian","sequence":"additional","affiliation":[{"name":"College of Data Science and Technology, Heilongjiang University, Harbin 150080, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Yuan","sequence":"additional","affiliation":[{"name":"College of Telecommunication and Electronic Engineering, Qiqihar University, Qiqihar 161006, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,4,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"5771","DOI":"10.1109\/TII.2021.3136580","article-title":"A hybrid blockchain-based log management scheme with nonrepudiation for smart grids","volume":"18","author":"Le","year":"2021","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"486","DOI":"10.1016\/j.future.2020.09.021","article-title":"An efficient and outsourcing-supported attribute-based access control scheme for edge-enabled smart healthcare","volume":"115","author":"Zhong","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"6500","DOI":"10.1109\/TII.2019.2931156","article-title":"An efficient attribute-based encryption scheme with policy update and file update in cloud computing","volume":"15","author":"Li","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1109\/TC.2020.3043950","article-title":"Efficient CP-ABE scheme with shared decryption in cloud storage","volume":"71","author":"Chen","year":"2020","journal-title":"IEEE Trans. Comput."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1767","DOI":"10.1109\/JSYST.2017.2667679","article-title":"User collusion avoidance CP-ABE with efficient attribute revocation for cloud storage","volume":"12","author":"Li","year":"2017","journal-title":"IEEE Syst. J."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Ezhilarasi, T.P., Sudheer, K.N., Latchoumi, T.P., and Balayesu, N. (2019, January 26\u201327). A secure data sharing using IDSS CP-ABE in cloud storage. Proceedings of the Advances in Industrial Automation and Smart Manufacturing, Kurnool, India.","DOI":"10.1007\/978-981-15-4739-3_92"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1016\/j.future.2022.08.017","article-title":"RMA-CPABE: A multi-authority CPABE scheme with reduced ciphertext size for IoT devices","volume":"138","author":"Chaudhary","year":"2023","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1007\/s00500-016-2330-8","article-title":"Multi-authority attribute-based encryption access control scheme with policy hidden for cloud storage","volume":"22","author":"Zhong","year":"2018","journal-title":"Soft Comput."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"821","DOI":"10.1109\/TII.2022.3167842","article-title":"Multi-Authority CP-ABE-Based Access Control Model for IoT-Enabled Healthcare Infrastructure","volume":"19","author":"Das","year":"2023","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_10","first-page":"1","article-title":"Revealed: How US and UK spy agencies defeat internet privacy and security","volume":"6","author":"Ball","year":"2013","journal-title":"Know Your Neighborhood"},{"key":"ref_11","unstructured":"Perlroth, N., Larson, J., and Shane, S. (The New York Times, 2013). NSA Able to Foil Basic Safeguards of Privacy on Web, The New York Times, pp. 1\u20138."},{"key":"ref_12","unstructured":"Greenwald, G. (2014). No Place to Hide: Edward Snowden, the NSA, and the US Surveillance State, Macmillan."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Mironov, I., and Stephens-Davidowitz, N. (2015, January 26\u201330). Cryptographic reverse firewalls. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Sofia, Bulgaria.","DOI":"10.1007\/978-3-662-46803-6_22"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"8681","DOI":"10.1109\/JIOT.2019.2923068","article-title":"Secure online\/offline data sharing framework for cloud-assisted industrial Internet of Things","volume":"6","author":"Miao","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_15","unstructured":"Sahai, A., and Waters, B. (2005, January 22\u201326). Fuzzy identity-based encryption. Proceedings of the Annual international conference on the theory and applications of cryptographic techniques, Aarhus, Denmark."},{"key":"ref_16","unstructured":"Goyal, V., Pandey, O., Sahai, A., and Waters, B. (November, January 30). Attribute-based encryption for fine-grained access control of encrypted data. Proceedings of the 13th ACM Conference on Computer and Communications Security, Lexandria, VA, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Bethencourt, J., Sahai, A., and Waters, B. (2007, January 20\u201323). Ciphertext-policy attribute-based encryption. Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP\u201907), Berkeley, CA, USA.","DOI":"10.1109\/SP.2007.11"},{"key":"ref_18","unstructured":"Chase, M. (2007, January 21\u201324). Multi-authority attribute based encryption. Proceedings of the Theory of Cryptography Conference, Amsterdam, The Netherlands."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Chase, M., and Chow, S.S.M. (2009, January 9\u201313). Improving privacy and security in multi-authority attribute-based encryption. Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago, IL, USA.","DOI":"10.1145\/1653662.1653678"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"2618","DOI":"10.1016\/j.ins.2010.03.004","article-title":"Secure threshold multi authority attribute based encryption without a central authority","volume":"180","author":"Lin","year":"2010","journal-title":"Inf. Sci."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"487","DOI":"10.1007\/s10207-014-0270-9","article-title":"Privacy-preserving personal health record using multi-authority attribute-based encryption with revocation","volume":"14","author":"Qian","year":"2015","journal-title":"Int. J. Inf. Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Guan, Y., Zhang, Z., and Li, F. (2019, January 15\u201317). Cryptographic reverse firewalls for identity-based encryption. Proceedings of the International Conference on Frontiers in Cyber Security, Xi\u2019an, China.","DOI":"10.1007\/978-981-15-0818-9_3"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Chen, R., Mu, Y., Yang, G., Susilo, W., Guo, F., and Zhang, M. (2016, January 4\u20138). Cryptographic reverse firewall via malleable smooth projective hash functions. Proceedings of the International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam.","DOI":"10.1007\/978-3-662-53887-6_31"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"101754","DOI":"10.1016\/j.sysarc.2020.101754","article-title":"Certificateless public key encryption with cryptographic reverse firewalls","volume":"109","author":"Zhou","year":"2020","journal-title":"J. Syst. Archit."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1109\/TCC.2021.3095498","article-title":"Searchable public-key encryption with cryptographic reverse firewalls for cloud storage","volume":"11","author":"Zhou","year":"2021","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Ma, H., Zhang, R., Yang, G., Song, Z., Sun, S., and Xiao, Y. (2018, January 3\u20137). Concessive online\/offline attribute based encryption with cryptographic reverse firewalls\u2014Secure and efficient fine-grained access control on corrupted machines. Proceedings of the European Symposium on Research in Computer Security, Barcelona, Spain.","DOI":"10.1007\/978-3-319-98989-1_25"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"159002","DOI":"10.1109\/ACCESS.2019.2950394","article-title":"Multi-authority non-monotonic KP-ABE with cryptographic reverse firewall","volume":"7","author":"Hong","year":"2019","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"114392","DOI":"10.1109\/ACCESS.2021.3104899","article-title":"OO-ABMS: Online\/Offline-Aided Attribute-Based Multi-Keyword Search","volume":"9","author":"Khan","year":"2021","journal-title":"IEEE Access"},{"key":"ref_29","first-page":"103101","article-title":"Verifiable online\/offline multi-keyword search for cloud-assisted Industrial Internet of Things","volume":"65","author":"Ali","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"104344","DOI":"10.1109\/ACCESS.2020.3000049","article-title":"Outsourcing attributed-based ranked searchable encryption with revocation for cloud storage","volume":"8","author":"Zhang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Shao, J., Zhu, Y., and Ji, Q. (2017, January 24\u201326). Privacy-preserving online\/offline and outsourced multi-authority attribute-based encryption. Proceedings of the 2017 IEEE\/ACIS 16th International Conference on Computer and Information Science (ICIS), Wuhan, China.","DOI":"10.1109\/ICIS.2017.7960007"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"3688","DOI":"10.1002\/sec.1574","article-title":"Online\/offline unbounded multi-authority attribute-based encryption for data sharing in mobile cloud computing","volume":"9","author":"Zhang","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_33","first-page":"8","article-title":"Outsourcing the decryption of abe ciphertexts","volume":"3","author":"Green","year":"2011","journal-title":"USENIX Secur. Symp."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1016\/j.future.2021.03.021","article-title":"A CP-ABE scheme based on multi-authority in hybrid clouds for mobile devices","volume":"121","author":"Xie","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Zhang, J., Gong, Q., Wei, Z., Wang, X., Yan, X., and Zhang, X. (2022, January 22\u201323). Efficient Multi-Authority Attribute-Based Encryption with Policy Hiding and Updating. Proceedings of the 2022 IEEE 10th International Conference on Computer Science and Network Technology (ICCSNT), Dalian, China.","DOI":"10.1109\/ICCSNT56096.2022.9972943"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"102654","DOI":"10.1016\/j.sysarc.2022.102654","article-title":"A traceable and revocable multi-authority access control scheme with privacy preserving for mHealth","volume":"130","author":"Zhang","year":"2022","journal-title":"J. Syst. Archit."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Datta, P., Dutta, R., and Mukhopadhyay, S. (2015, January 5\u20138). Fully secure online\/offline predicate and attribute-based encryption. Proceedings of the International Conference on Information Security Practice and Experience, Beijing, China.","DOI":"10.1007\/978-3-319-17533-1_23"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/4\/616\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:10:04Z","timestamp":1760123404000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/25\/4\/616"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,4]]},"references-count":37,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,4]]}},"alternative-id":["e25040616"],"URL":"https:\/\/doi.org\/10.3390\/e25040616","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,4]]}}}