ShieldDB: An Encrypted Document Database with Padding Countermeasures

03/13/2020
by   Viet Vo, et al.
0

The security of our data stores is underestimated in current practice, which resulted in many large-scale data breaches. To change the status quo, this paper presents the design of ShieldDB, an encrypted document database. ShieldDB adapts the searchable encryption technique to preserve the search functionality over encrypted documents without having much impact on its scalability. However, merely realising such a theoretical primitive suffers from real-world threats, where a knowledgeable adversary can exploit the leakage (aka access pattern to the database) to break the claimed protection on data confidentiality. To address this challenge in practical deployment, ShieldDB is designed with tailored padding countermeasures. Unlike prior works, we target a more realistic adversarial model, where the database gets updated continuously, and the adversary can monitor it at an (or multiple) arbitrary time interval(s). ShieldDB's padding strategies ensure that the access pattern to the database is obfuscated all the time. Additionally, ShieldDB provides other advanced features, including forward privacy, re-encryption, and flushing, to further improve its security and efficiency. We present a full-fledged implementation of ShieldDB and conduct intensive evaluations on Azure Cloud.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/10/2021

Equi-Joins Over Encrypted Data for Series of Queries

Encryption provides a method to protect data outsourced to a DBMS provid...
research
09/29/2022

Data Querying with Ciphertext Policy Attribute Based Encryption

Data encryption limits the power and efficiency of queries. Direct proce...
research
09/19/2022

Encrypted Semantic Communication Using Adversarial Training for Privacy Preserving

Semantic communication is implemented based on shared background knowled...
research
08/28/2017

T-DB: Toward Fully Functional Transparent Encrypted Databases in DBaaS Framework

Individuals and organizations tend to migrate their data to clouds, espe...
research
05/11/2019

GraphSE^2: An Encrypted Graph Database for Privacy-Preserving Social Search

In this paper, we propose GraphSE^2, an encrypted graph database for onl...
research
01/07/2020

Towards Practical Encrypted Network Traffic Pattern Matching for Secure Middleboxes

Network Function Virtualisation (NFV) advances the development of compos...
research
08/29/2019

How Much Does GenoGuard Really "Guard"? An Empirical Analysis of Long-Term Security for Genomic Data

Due to its hereditary nature, genomic data is not only linked to its own...

Please sign up or login with your details

Forgot password? Click here to reset