Practical Passive Leakage-abuse Attacks Against Symmetric Searchable Encryption - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

Practical Passive Leakage-abuse Attacks Against Symmetric Searchable Encryption

Résumé

Symmetric Searchable Encryption (SSE) schemes solve efficiently the problem of securely outsourcing client data with search functionality. These schemes are provably secure with respect to an explicit leakage profile; however, determining how much information can be inferred in practice from this leakage remains difficult. First, we recall the leakage hierarchy introduced in 2015 by Cash et al. Second, we present complete practical attacks on SSE schemes of L4, L3 and L2 leakage profiles which are deployed in commercial cloud solutions. Our attacks are passive and only assume the knowledge of a small sample of plaintexts. Moreover, we show their devastating effect on real-world data sets since, regardless of the leakage profile, an adversary knowing a mere 1% of the document set is able to retrieve 90% of documents whose content is revealed over 70%. Then, we further extend the analysis of existing attacks to highlight the gap of security that exists between L2-and L1-SSE and give some simple countermeasures to prevent our attacks.
Fichier principal
Vignette du fichier
GABL17.pdf (301.09 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01689780 , version 1 (22-01-2018)

Identifiants

Citer

Matthieu Giraud, Alexandre Anzala-Yamajako, Olivier Bernard, Pascal Lafourcade. Practical Passive Leakage-abuse Attacks Against Symmetric Searchable Encryption. 14th International Conference on Security and Cryptography SECRYPT 2017, Jul 2017, Madrid, France. ⟨10.5220/0006461202000211⟩. ⟨hal-01689780⟩
231 Consultations
233 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More