IHOP: Improved Statistical Query Recovery against Searchable Symmetric Encryption through Quadratic Optimization

10/08/2021
by   Simon Oya, et al.
0

Searchable Symmetric Encryption (SSE) schemes allow a client to perform secure searches over encrypted databases on a remote server. These schemes leak certain information that an honest-but-curious service provider can use to recover the keywords of the client's queries. Effective query recovery attacks typically rely on auxiliary ground-truth information about the queries or dataset. Query recovery is also possible under the weaker statistical auxiliary information assumption, although statistical-based attacks achieve lower accuracy and are not considered a serious threat. In this work we present IHOP, a statistical-based query recovery attack that formulates query recovery as a quadratic optimization problem and reaches a solution by iterating over linear assignment problems. We show that IHOP outperforms all other statistical-based query recovery attacks on SSE schemes with typical access and search pattern leakage, reaching query recovery accuracies around 80 against access-pattern obfuscation defenses and show that it still achieves reasonable recovery rates, outperforming existing attacks in this scenario. Finally, we use IHOP in a frequency-only leakage setting where the client's queries are correlated, and show that our attack can exploit query dependencies even when PANCAKE, a recent frequency-hiding defense by Grubbs et al., is applied. Our findings indicate that statistical query recovery attacks pose a severe threat to privacy-preserving SSE schemes.

READ FULL TEXT
research
10/07/2020

Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable Encryption

Recent Searchable Symmetric Encryption (SSE) schemes enable secure searc...
research
02/18/2021

Obfuscated Access and Search Patterns in Searchable Encryption

Searchable Symmetric Encryption (SSE) allows a data owner to securely ou...
research
02/11/2023

High Recovery with Fewer Injections: Practical Binary Volumetric Injection Attacks against Dynamic Searchable Encryption

Searchable symmetric encryption enables private queries over an encrypte...
research
07/03/2023

Passive Query-Recovery Attack Against Secure Conjunctive Keyword Search Schemes

While storing documents on the cloud can be attractive, the question rem...
research
06/27/2023

A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed Documents

Cloud data storage solutions offer customers cost-effective and reduced ...
research
08/15/2020

Practical Volume-Based Attacks on Encrypted Databases

Recent years have seen an increased interest towards strong security pri...
research
07/15/2019

Hands Off my Database: Ransomware Detection in Databases through Dynamic Analysis of Query Sequences

Ransomware is an emerging threat which imposed a $ 5 billion loss in 201...

Please sign up or login with your details

Forgot password? Click here to reset