AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

Order-Revealing Encryption: File-Injection Attack and Forward Security

School of Computer Science, Fudan University, Shanghai 201203, China
State Key Laboratory of Integrated Services Networks, Xidian University, Xi’an 710071, China
State Key Laboratory of Cryptology, Beijing 100878, China

A preliminary version of the paper was published in the Proceedings of ESORICS 2018.

Show Author Information

Abstract

Order-preserving encryption (OPE) and order-revealing encryption (ORE) are among the core ingredients for encrypted databases (EDBs). In this work, we study the leakage of OPE and ORE and their forward security. We propose generic yet powerful file-injection attacks (FIAs) on OPE/ORE, aimed at the situations of possessing order by and range queries. Our FIAs only exploit the ideal leakage of OPE/ORE (in particular, no need of data denseness or frequency). We also improve their efficiency with the frequency statistics using a hierarchical idea such that the high-frequency values will be recovered more quickly. We conduct some experiments on real datasets to test the performance, and the results show that our FIAs can cause an extreme hazard on most of the existing OPEs and OREs with high efficiency and 100% recovery rate. We then formulate forward security of ORE, and propose a practical compilation framework for achieving forward secure ORE to resist the perniciousness of FIA. The compilation framework can transform most of the existing OPEs/OREs into forward secure OREs, with the goal of minimizing the extra burden incurred on computation and storage. We also present its security proof, and execute some experiments to analyze its performance. The proposed compilation is highly efficient and forward secure.

Electronic Supplementary Material

Download File(s)
jcst-36-4-877-Highlights.pdf (129.3 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 877-895

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Li Y, Wang X-C, Huang L, et al. Order-Revealing Encryption: File-Injection Attack and Forward Security. Journal of Computer Science and Technology, 2021, 36(4): 877-895. https://doi.org/10.1007/s11390-020-0060-y

952

Views

0

Crossref

0

Web of Science

0

Scopus

1

CSCD

Received: 13 December 2019
Accepted: 29 December 2020
Published: 05 July 2021
©Institute of Computing Technology, Chinese Academy of Sciences 2021