Passive Attacks Against Searchable Encryption

被引:72
|
作者
Ning, Jianting [1 ]
Xu, Jia [2 ]
Liang, Kaitai [3 ]
Zhang, Fan [4 ,5 ,6 ]
Chang, Ee-Chien [1 ]
机构
[1] Natl Univ Singapore, Dept Comp Sci, Singapore 117417, Singapore
[2] NUS, Singtel Cyber Secur Res & Dev Lab, Singapore 117602, Singapore
[3] Univ Surrey, Dept Comp Sci, Guildford GU2 7XH, Surrey, England
[4] Zhejiang Univ, Coll Informat Sci & Elect Engn, Hangzhou 310027, Zhejiang, Peoples R China
[5] Zhejiang Univ, Inst Cyber Secur Res, Hangzhou 310027, Zhejiang, Peoples R China
[6] Natl Univ Singapore, Sch Comp, Singapore 117417, Singapore
基金
英国工程与自然科学研究理事会; 中国国家自然科学基金; 新加坡国家研究基金会;
关键词
Searchable symmetric encryption; passive attacks; search query privacy; leakage of file-access pattern;
D O I
10.1109/TIFS.2018.2866321
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Searchable encryption (SE) provides a privacy-preserving mechanism for data users to search over encrypted data stored on a remote server. Researchers have designed a number of SE schemes with high efficiency yet allowing some degree of leakage profile to the remote server. The leakage, however, should be further measured to allow us to understand what types of attacks an SE scheme would encounter. This paper considers passive attacks that make inferences based on prior knowledge and observations on queries issued by users. This is in contrast to previously studied active attacks that adaptively inject files and queries. We consider several assumptions on the types or prior knowledge the attacker possessed and propose a few passive attacks. In particular, under the "full-fledged" assumption, the keyword recovery rate of our attack is optimal in the sense that it is equal to the theoretical upper bound. We further present several enhanced attacks under other weaker assumptions on various levels of the prior knowledge that the attacker can obtain, in which the keyword recovery rates are optimal or nearly optimal (i.e., approaching the theoretical upper bound). In addition, we provide extensive experiments to show the "power" of our passive attacks. This paper highlights the importance of minimizing the prior knowledge of a server and the leakage of search queries. It also shows that simply distorting the frequency of the keyword to hold against our passive attacks may not scale well.
引用
收藏
页码:789 / 802
页数:14
相关论文
共 50 条
  • [41] Generic Certificateless Encryption Secure Against Malicious-but-Passive KGC Attacks in the Standard Model
    黄琼
    王石
    Journal of Computer Science & Technology, 2010, 25 (04) : 807 - 823
  • [42] Partitioned Searchable Encryption
    Barthel, Jim
    Beunardeau, Marc
    Rosie, Razvan
    Sahu, Rajeev Anand
    PROVABLE AND PRACTICAL SECURITY, PROVSEC 2021, 2021, 13059 : 63 - 79
  • [43] Cryptanalysis of "An Efficient Searchable Encryption Against Keyword Guessing Attacks for Shareable Electronic Medical Records in Cloud-Based System"
    Li, Chun-Ta
    Lee, Cheng-Chi
    Weng, Chi-Yao
    Wu, Tsu-Yang
    Chen, Chien-Ming
    INFORMATION SCIENCE AND APPLICATIONS 2017, ICISA 2017, 2017, 424 : 282 - 289
  • [44] Searchable encryption : A survey
    Sharma, Dhruti
    INFORMATION SECURITY JOURNAL, 2023, 32 (02): : 76 - 119
  • [45] Searchable Encryption Schemes
    Premasathian, Nol
    Choto, Somsak
    2012 9TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2012, : 147 - 150
  • [46] Survey on the searchable encryption
    Jia, Chun-Fu
    Liu, Zhe-Li
    Li, Jin
    Li, Min
    Ruan Jian Xue Bao/Journal of Software, 2015, 26 (01): : 109 - 128
  • [47] Decryptable searchable encryption
    Fuhr, Thomas
    Paillier, Pascal
    PROVABLE SECURITY, PROCEEDINGS, 2007, 4784 : 228 - 236
  • [48] Improved File-injection Attacks on Searchable Encryption Using Finite Set Theory
    Wang, Gaoli
    Cao, Zhenfu
    Dong, Xiaolei
    COMPUTER JOURNAL, 2021, 64 (08): : 1264 - 1276
  • [49] Off-Line Keyword Guessing Attacks on Searchable Encryption with Keyword-Recoverability
    Yoon, Eun-Jun
    Yoo, Kee-Young
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2010, E93D (07): : 1995 - 1996
  • [50] Keyword guessing attacks on secure searchable public key encryption schemes with a designated tester
    Yau, Wei-Chuen
    Phan, Raphael C. -W.
    Heng, Swee-Huay
    Goi, Bok-Min
    INTERNATIONAL JOURNAL OF COMPUTER MATHEMATICS, 2013, 90 (12) : 2581 - 2587