Leakage Inversion: Towards Quantifying Privacy in Searchable Encryption
Leakage Inversion: Towards Quantifying Privacy in Searchable Encryption
复制标题
泄漏反演:量化可搜索加密中的隐私
DOI:
10.1145/3548606.3560593
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Psomas, Alexandros
中科院分区:
文献类型:
--
作者:
Kornaropoulos, Evgenios M.;Moyer, Nathaniel;Papamanthou, Charalampos;Psomas, Alexandros
Searchable encryption (SE) provides cryptographic guarantees that a user can efficiently search over encrypted data while only disclosing patterns about the data, also known as leakage. Recently, the community has developed leakage-abuse attacks that shed light on what an attacker can infer about the underlying sensitive information using the aforementioned leakage. A glaring missing piece in this effort is the absence of a systematic and rigorous method that quantifies the privacy guarantees of SE.In this work, we put forth the notion of leakage inversion that quantifies privacy in SE. Our insight is that the leakage is a function and, thus, one can define its inverse which corresponds to the collection of databases that reveal structurally equivalent patterns to the original plaintext database. We call this collection of databases the reconstruction space and we rigorously study its properties that impact the privacy of an SE scheme such as the entropy of the reconstruction space and the distance of its members from the original plaintext database. Leakage inversion allows for a foundational algorithmic analysis of the privacy offered by SE and we demonstrate this by defining closed-form expressions and lower/upper bounds on the properties of the reconstruction space for both keyword-based and range-based databases. We use leakage inversion in three scenarios: (i) we quantify the impact that auxiliary information, a typical cryptanalytic assumption, has to the overall privacy, (ii) we quantify how privacy is affected in case of restricting range schemes to respond to a limited number of queries, and (iii) we study the efficiency vs. privacy trade-off offered by proposed padding defenses. We use real-world databases in all three scenarios and we draw theoretically-grounded new insights about the interplay between leakage, attacks, defenses, and efficiency.
登录
查看更多内容
影响因子:
--
作者:
A. Boldyreva;Tianxin Tang
通讯作者:
A. Boldyreva;Tianxin Tang
DOI:
--
发表时间:
2021
期刊:
International Conference on the Theory and Application of Cryptographic Techniques
影响因子:
--
作者:
Marilyn George;S. Kamara;Tarik Moataz
通讯作者:
Tarik Moataz
DOI:
--
发表时间:
2021
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
作者:
Angèle Bossuat;Raphael Bost;Pierre;Brice Minaud;Michael Reichle
通讯作者:
Michael Reichle
DOI:
10.1145/3035918.3035948
发表时间:
2017-05
期刊:
Proceedings of the 2017 ACM International Conference on Management of Data
影响因子:
--
作者:
Caleb Horst;Ryo Kikuchi;Keita Xagawa
通讯作者:
Caleb Horst;Ryo Kikuchi;Keita Xagawa
DOI:
10.1007/978-3-319-96131-6
发表时间:
2020
期刊:
The Science of Quantitative Information Flow
影响因子:
--
作者:
M. Alvim;K. Chatzikokolakis;Annabelle McIver;Carroll Morgan;C. Palamidessi;Geoffrey Smith
通讯作者:
Geoffrey Smith