Certificateless Encryption Supporting Equality Test with Cryptographic Reverse Firewalls in Smart City
Article Information
Abstract
In the context of smart cities, sensors are pivotal for the collection and analysis of health data within smart healthcare systems. Despite their importance, securing this data for cloud storage poses significant challenges, particularly in terms of data searchability and encryption. Our paper introduces a novel solution, namely certificateless encryption supporting equality test with cryptographic reverse firewalls (CLE-ET-CRF). This protocol allows cloud servers to perform equality tests on encrypted data without compromising its confidentiality, effectively mitigating risks like offline message recovery attacks (OMRA) and algorithm substitution attacks (ASAs). By eliminating the need for traditional certificate management and addressing key escrow concerns, CLE-ET-CRF provides a secure, efficient, and privacy-preserving mechanism for managing healthcare data in smart city ecosystems. Our evaluation confirms that the protocol meets the high standards required for privacy and efficiency in smart healthcare applications.
Graphical Abstract
Keywords
Data Availability Statement
Funding
Conflicts of Interest
AI Use Statement
Ethical Approval and Consent to Participate
References
- Lopez Martinez, A., Gil P\'erez, M., & Ruiz-Mart\'inez, A. (2023). A Comprehensive Review of the State-of-the-Art on Security and Privacy Issues in Healthcare. ACM Computing Surveys, 55(12), 1-38.
[CrossRef] [Google Scholar] - Chithaluru, P., Al-Turjman, F., Kumar, M., & Stephan, T. (2020). I-AREOR: An energy-balanced clustering protocol for implementing green IoT in smart cities. Sustainable cities and society, 61, 102254.
[CrossRef] [Google Scholar] - Zovko, K., \v{Seri\'c, L., Perkovi\'c, T., Belani, H., & \v{Soli\'c, P. (2023). IoT and health monitoring wearable devices as enabling technologies for sustainable enhancement of life quality in smart environments. Journal of Cleaner Production, 413, 137506.
[CrossRef] [Google Scholar] - Vishnupriya, G., Anusha, S., & Kayikci, S. (2024). An efficient and secure wearable sensor based remote healthcare monitoring system using adaptive dilated transformer Bi-LSTM with gated recurrent unit. Transactions on Emerging Telecommunications Technologies, 35(2), e4932.
[CrossRef] [Google Scholar] - Rejeb, A., Rejeb, K., Treiblmaier, H., Appolloni, A., Alghamdi, S., Alhasawi, Y., & Iranmanesh, M. (2023). The Internet of Things (IoT) in healthcare: Taking stock and moving forward. Internet of Things, 22, 100721.
[CrossRef] [Google Scholar] - Elhabob, R., Eltayieb, N., Xiong, H., Khan, F., Bashir, A. K., Kumari, S., ... & Kumar, S. (2024). Equality test public key encryption with cryptographic reverse firewalls for cloud-based E-commerce. IEEE Transactions on Consumer Electronics, 70(4), 6763-6775.
[CrossRef] [Google Scholar] - Khan, S., Khan, M., Khan, M. A., Khan, M. A., Wang, L., & Wu, K. (2025). A blockchain-enabled AI-driven secure searchable encryption framework for medical IoT systems. IEEE Journal of Biomedical and Health Informatics.
[CrossRef] [Google Scholar] - Abdulmalek, S., Nasir, A., Jabbar, W. A., Almuhaya, M. A., Bairagi, A. K., Khan, M. A. M., & Kee, S. H. (2022, October). IoT-based healthcare-monitoring system towards improving quality of life: A review. Healthcare, 10(10), 1993.
[CrossRef] [Google Scholar] - Mei, Q., Yang, M., Chen, J., Wang, L., & Xiong, H. (2022). Expressive data sharing and self-controlled fine-grained data deletion in cloud-assisted IoT. IEEE Transactions on Dependable and Secure Computing, 20(3), 2625-2640.
[CrossRef] [Google Scholar] - Fong, B., Kim, H., & Sai, V. (2023). Consumer healthcare technologies in smart cities. IEEE Consumer Electronics Magazine, 12(4), 63-65.
[CrossRef] [Google Scholar] - Wang, L., Lin, Y., Yao, T., Xiong, H., & Liang, K. (2023). FABRIC: Fast and secure unbounded cross-system encrypted data sharing in cloud computing. IEEE Transactions on Dependable and Secure Computing, 20(6), 5130-5142.
[CrossRef] [Google Scholar] - Elhabob, R., Eltayieb, N., Xiong, H., & Kumari, S. (2024). Equality test on identity-based encryption with cryptographic reverse firewalls for telemedicine systems. IEEE Internet of Things Journal, 12(2), 2106-2121.
[CrossRef] [Google Scholar] - Boneh, D., Di Crescenzo, G., Ostrovsky, R., & Persiano, G. (2004, May). Public key encryption with keyword search. In International conference on the theory and applications of cryptographic techniques (pp. 506-522). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Xiong, H., Wang, H., Meng, W., & Yeh, K. H. (2023). Attribute-based data sharing scheme with flexible search functionality for cloud-assisted autonomous transportation system. IEEE Transactions on Industrial Informatics, 19(11), 10977-10986.
[CrossRef] [Google Scholar] - Zhou, Y., Guo, J., & Li, F. (2020). Certificateless public key encryption with cryptographic reverse firewalls. Journal of Systems Architecture, 109, 101754.
[CrossRef] [Google Scholar] - Yang, G., Tan, C. H., Huang, Q., & Wong, D. S. (2010, March). Probabilistic public key encryption with equality test. In Cryptographers’ track at the RSA conference (pp. 119-131). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Lioy, A., Marian, M., Moltchanova, N., & Pala, M. (2006). PKI past, present and future. International Journal of Information Security, 5(1), 18-29.
[CrossRef] [Google Scholar] - Ma, S. (2016). Identity-based encryption with outsourced equality test in cloud computing. Information Sciences, 328, 389-402.
[CrossRef] [Google Scholar] - Qu, H., Yan, Z., Lin, X. J., Zhang, Q., & Sun, L. (2018). Certificateless public key encryption with equality test. Information Sciences, 462, 76-92.
[CrossRef] [Google Scholar] - Taha, M., Zhong, T., Elhabob, R., Xiong, H., Kumari, S., Chen, C. M., & Alenazi, M. J. (2025). Identity-based searchable encryption with cryptographic reverse firewalls for IoT-based healthcare systems. Computers and Electrical Engineering, 124, 110404.
[CrossRef] [Google Scholar] - Zhao, Z., Susilo, W., Wang, B., & Zeng, K. (2023). Public-key encryption with tester verifiable equality test for cloud computing. IEEE Transactions on Cloud Computing, 11(4), 3396-3406.
[CrossRef] [Google Scholar] - Xiong, H., Hou, Y., Huang, X., Zhao, Y., & Chen, C. M. (2021). Heterogeneous signcryption scheme from IBC to PKI with equality test for WBANs. IEEE Systems Journal, 16(2), 2391-2400.
[CrossRef] [Google Scholar] - Zhao, M., Ding, Y., Tang, S., Liang, H., Yang, C., & Wang, H. (2023). Dual-server certificateless public key encryption with authorized equality test for outsourced IoT data. Journal of Information Security and Applications, 73, 103441.
[CrossRef] [Google Scholar] - Elhabob, R., Taha, M., Xiong, H., Khan, M. K., Kumari, S., & Chaudhary, P. (2024). Pairing-free certificateless public key encryption with equality test for Internet of Vehicles. Computers and Electrical Engineering, 116, 109140.
[CrossRef] [Google Scholar] - Tang, Q. (2012). Public key encryption schemes supporting equality test with authorisation of different granularity. International journal of applied cryptography, 2(4), 304-321.
[CrossRef] [Google Scholar] - Ling, Y., Ma, S., Huang, Q., Li, X., & Ling, Y. (2020). Group public key encryption with equality test against offline message recovery attack. Information Sciences, 510, 16-32.
[CrossRef] [Google Scholar] - Lu, J., Li, H., Huang, J., Ma, S., Au, M. H. A., & Huang, Q. (2024). An Identity-Based Encryption with Equality Test scheme for healthcare social apps. Computer Standards & Interfaces, 87, 103759.
[CrossRef] [Google Scholar] - Tang, Q., & Yung, M. (2017, October). Cliptography: Post-snowden cryptography. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security (pp. 2615-2616).
[CrossRef] [Google Scholar] - Bellare, M., Paterson, K. G., & Rogaway, P. (2014, August). Security of symmetric encryption against mass surveillance. In Annual cryptology conference (pp. 1-19). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Mironov, I., & Stephens-Davidowitz, N. (2015, April). Cryptographic reverse firewalls. In Annual international conference on the theory and applications of cryptographic techniques (pp. 657-686). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Song, D. X., Wagner, D., & Perrig, A. (2000, May). Practical techniques for searches on encrypted data. In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000 (pp. 44-55). IEEE.
[CrossRef] [Google Scholar] - Ma, S., Huang, Q., Zhang, M., & Yang, B. (2014). Efficient public key encryption with equality test supporting flexible authorization. IEEE Transactions on Information Forensics and Security, 10(3), 458-470.
[CrossRef] [Google Scholar] - Ma, S., Ye, Z., Huang, Q., & Jiang, C. (2024). Controllable Forward Secure Identity-based Encryption with Equality Test in Privacy-preserving Text Similarity Analysis. Information Sciences, 662, 120099.
[CrossRef] [Google Scholar] - Xiong, H., Zhao, Y., Hou, Y., Huang, X., Jin, C., Wang, L., & Kumari, S. (2020). Heterogeneous signcryption with equality test for IIoT environment. IEEE Internet of Things Journal, 8(21), 16142-16152.
[CrossRef] [Google Scholar] - Jin, C., Qin, W., Chen, Z., Sun, K., Chen, G., Shan, J., & Chen, L. (2024). Heterogeneous signcryption scheme with equality test from CLC to PKI for IoV. Computer Communications, 220, 149-159.
[CrossRef] [Google Scholar] - Qu, Z., Kumari, S., Obaidat, M. S., Alzahrani, B. A., & Xiong, H. (2023). Traceable attribute-based encryption with equality test for cloud enabled e-health system. IEEE journal of biomedical and health informatics, 28(9), 5033-5042.
[CrossRef] [Google Scholar] - Al-Riyami, S. S., & Paterson, K. G. (2003, November). Certificateless public key cryptography. In International conference on the theory and application of cryptology and information security (pp. 452-473). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Chen, R., Mu, Y., Yang, G., Susilo, W., Guo, F., & Zhang, M. (2016, November). Cryptographic reverse firewall via malleable smooth projective hash functions. In International conference on the theory and application of cryptology and information security (pp. 844-876). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Gupta, S., Chithaluru, P., El Barachi, M., & Kumar, M. (2024). Secure data access using blockchain technology through IoT cloud and fabric environment. Security and Privacy, 7(2), e356.
[CrossRef] [Google Scholar] - Hu, B., Chen, Y., Yu, H., Meng, L., & Duan, Z. (2021). Blockchain-enabled data-sharing scheme for consumer IoT applications. IEEE Consumer Electronics Magazine, 11(2), 77-87.
[CrossRef] [Google Scholar] - Hou, Y., Huang, X., Chen, Y., Kumar, S., & Xiong, H. (2021). Heterogeneous signcryption scheme supporting equality test from PKI to CLC toward IoT. Transactions on Emerging Telecommunications Technologies, 32(8), e4190.
[CrossRef] [Google Scholar] - Zhou, Y., Hu, Z., & Li, F. (2021). Searchable public-key encryption with cryptographic reverse firewalls for cloud storage. IEEE transactions on cloud computing, 11(1), 383-396.
[CrossRef] [Google Scholar] - Barreto, P. S., Galbraith, S. D., hÉigeartaigh, C. Ó., & Scott, M. (2007). Efficient pairing computation on supersingular abelian varieties. Designs, Codes and Cryptography, 42(3), 239-271.
[CrossRef] [Google Scholar] - Oliveira, L. B., Aranha, D. F., Gouvêa, C. P., Scott, M., Câmara, D. F., López, J., & Dahab, R. (2011). TinyPBC: Pairings for authenticated identity-based non-interactive key distribution in sensor networks. Computer communications, 34(3), 485-493.
[CrossRef] [Google Scholar] - Gura, N., Patel, A., Wander, A., Eberle, H., & Shantz, S. C. (2004, August). Comparing elliptic curve cryptography and RSA on 8-bit CPUs. In International workshop on cryptographic hardware and embedded systems (pp. 119-132). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Shim, K. A., Lee, Y. R., & Park, C. M. (2013). EIBAS: An efficient identity-based broadcast authentication scheme in wireless sensor networks. Ad Hoc Networks, 11(1), 182-189.
[CrossRef] [Google Scholar] - Crossbow Technology Inc. (2005). MICA2 OEM Edition datasheet. Retrieved from http://www.cmt-gmbh.de/Produkte/WirelessSensorNetworks/Datenblaetter/MICA2_OEM_Edition_Datasheet.pdf
[Google Scholar] - Shim, K. A. (2014). S2DRP: Secure implementations of distributed reprogramming protocol for wireless sensor networks. Ad Hoc Networks, 19, 1-8.
[CrossRef] [Google Scholar] - Cao, X., Kou, W., Dang, L., & Zhao, B. (2008). IMBAS: Identity-based multi-user broadcast authentication in wireless sensor networks. Computer communications, 31(4), 659-667.
[CrossRef] [Google Scholar]
Cite This Article
TY - JOUR AU - Elhabob, Rashad AU - Elkhalil, Ahmed AU - Hadabi, Abdalla AU - Taha, Mazin AU - Hundera, Negalign Wake AU - Eltayieb, Nabeil PY - 2026 DA - 2026/03/30 TI - Certificateless Encryption Supporting Equality Test with Cryptographic Reverse Firewalls in Smart City JO - Journal of Reliable and Secure Computing T2 - Journal of Reliable and Secure Computing JF - Journal of Reliable and Secure Computing VL - 2 IS - 1 SP - 66 EP - 82 DO - 10.62762/JRSC.2025.581803 UR - https://www.icck.org/article/abs/JRSC.2025.581803 KW - equality test KW - searchable encryption KW - smart healthcare KW - certificateless KW - cloud server KW - CRF AB - In the context of smart cities, sensors are pivotal for the collection and analysis of health data within smart healthcare systems. Despite their importance, securing this data for cloud storage poses significant challenges, particularly in terms of data searchability and encryption. Our paper introduces a novel solution, namely certificateless encryption supporting equality test with cryptographic reverse firewalls (CLE-ET-CRF). This protocol allows cloud servers to perform equality tests on encrypted data without compromising its confidentiality, effectively mitigating risks like offline message recovery attacks (OMRA) and algorithm substitution attacks (ASAs). By eliminating the need for traditional certificate management and addressing key escrow concerns, CLE-ET-CRF provides a secure, efficient, and privacy-preserving mechanism for managing healthcare data in smart city ecosystems. Our evaluation confirms that the protocol meets the high standards required for privacy and efficiency in smart healthcare applications. SN - 3070-6424 PB - Institute of Central Computation and Knowledge LA - English ER -
@article{Elhabob2026Certificat,
author = {Rashad Elhabob and Ahmed Elkhalil and Abdalla Hadabi and Mazin Taha and Negalign Wake Hundera and Nabeil Eltayieb},
title = {Certificateless Encryption Supporting Equality Test with Cryptographic Reverse Firewalls in Smart City},
journal = {Journal of Reliable and Secure Computing},
year = {2026},
volume = {2},
number = {1},
pages = {66-82},
doi = {10.62762/JRSC.2025.581803},
url = {https://www.icck.org/article/abs/JRSC.2025.581803},
abstract = {In the context of smart cities, sensors are pivotal for the collection and analysis of health data within smart healthcare systems. Despite their importance, securing this data for cloud storage poses significant challenges, particularly in terms of data searchability and encryption. Our paper introduces a novel solution, namely certificateless encryption supporting equality test with cryptographic reverse firewalls (CLE-ET-CRF). This protocol allows cloud servers to perform equality tests on encrypted data without compromising its confidentiality, effectively mitigating risks like offline message recovery attacks (OMRA) and algorithm substitution attacks (ASAs). By eliminating the need for traditional certificate management and addressing key escrow concerns, CLE-ET-CRF provides a secure, efficient, and privacy-preserving mechanism for managing healthcare data in smart city ecosystems. Our evaluation confirms that the protocol meets the high standards required for privacy and efficiency in smart healthcare applications.},
keywords = {equality test, searchable encryption, smart healthcare, certificateless, cloud server, CRF},
issn = {3070-6424},
publisher = {Institute of Central Computation and Knowledge}
}
Publisher's Note
ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and Permissions
Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Portico