Leakage-Abuse Attacks against Order-Revealing Encryption

Leakage-Abuse Attacks against Order-Revealing Encryption
复制标题

DOI:
10.1109/sp.2017.44
复制
发表时间:
2017-05
期刊:
2017 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Paul Grubbs;Kevin Sekniqi;Vincent Bindschaedler;Muhammad Naveed;Thomas Ristenpart
Paul Grubbs;Kevin Sekniqi;Vincent Bindschaedler;Muhammad Naveed;Thomas Ristenpart
中科院分区:
其他
文献类型:
--
作者:
Paul Grubbs;Kevin Sekniqi;Vincent Bindschaedler;Muhammad Naveed;Thomas Ristenpart

文献摘要

被引文献

相似文献

顺序保持加密及其泛化顺序揭示加密(OPE/ORE)允许排序、执行范围查询和过滤数据--所有这些都只能访问密文。但OPE和ORE密文必然会泄露有关明文的信息,以及它们在实践中提供的安全级别一直不清楚。在这项工作中,我们引入了新的泄漏滥用攻击,从OPE/OR加密的数据库中恢复明文。我们新的攻击背后是一个框架,在这个框架中,我们将对手的挑战描述为一个不交叉的两方匹配问题。这允许根据特定方案的泄漏配置文件轻松定制攻击。在一个客户记录的案例研究中,我们显示了攻击可以恢复数据库中保存的99%的名字、97%的姓氏和90%的生日,尽管所有的值都是使用实践中最广泛使用的OPE方案加密的。我们还展示了对最近的频率隐藏Kerschbaum方案的第一次攻击,以前没有对该方案进行过攻击。我们的攻击在大多数情况下恢复了频繁出现的明文。
Order-preserving encryption and its generalization order-revealing encryption (OPE/ORE) allow sorting, performing range queries, and filtering data — all while only having access to ciphertexts. But OPE and ORE ciphertexts necessarily leak information about plaintexts, and what level of security they provide in practice has been unclear. In this work, we introduce new leakage-abuse attacks that recover plaintexts from OPE/ORE-encrypted databases. Underlying our new attacks is a framework in which we cast the adversary's challenge as a non-crossing bipartite matching problem. This allows easy tailoring of attacks to a specific scheme's leakage profile. In a case study of customer records, we show attacks that recover 99% of first names, 97% of last names, and 90% of birthdates held in a database, despite all values being encrypted with the OPE scheme most widely used in practice. We also show the first attack against the recent frequency-hiding Kerschbaum scheme, to which no prior attacks have been demonstrated. Our attack recovers frequently occurring plaintexts most of the time.