Hiding Access-pattern is Not Enough! Veil: A Storage and Communication Efficient Volume-Hiding Algorithm

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Han, Shanshan, Chakraborty, Vishal, Goodrich, Michael, Mehrotra, Sharad, Sharma, Shantanu
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916137203138560
author Han, Shanshan
Chakraborty, Vishal
Goodrich, Michael
Mehrotra, Sharad
Sharma, Shantanu
author_facet Han, Shanshan
Chakraborty, Vishal
Goodrich, Michael
Mehrotra, Sharad
Sharma, Shantanu
contents This paper addresses volume leakage (i.e., leakage of the number of records in the answer set) when processing keyword queries in encrypted key-value (KV) datasets. Volume leakage, coupled with prior knowledge about data distribution and/or previously executed queries, can reveal both ciphertexts and current user queries. We develop a solution to prevent volume leakage, entitled Veil, that partitions the dataset by randomly mapping keys to a set of equi-sized buckets. Veil provides a tunable mechanism for data owners to explore a trade-off between storage and communication overheads. To make buckets indistinguishable to the adversary, Veil uses a novel padding strategy that allow buckets to overlap, reducing the need to add fake records. Both theoretical and experimental results show Veil to significantly outperform existing state-of-the-art.
format Preprint
id arxiv_https___arxiv_org_abs_2310_12491
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Hiding Access-pattern is Not Enough! Veil: A Storage and Communication Efficient Volume-Hiding Algorithm
Han, Shanshan
Chakraborty, Vishal
Goodrich, Michael
Mehrotra, Sharad
Sharma, Shantanu
Databases
Cryptography and Security
This paper addresses volume leakage (i.e., leakage of the number of records in the answer set) when processing keyword queries in encrypted key-value (KV) datasets. Volume leakage, coupled with prior knowledge about data distribution and/or previously executed queries, can reveal both ciphertexts and current user queries. We develop a solution to prevent volume leakage, entitled Veil, that partitions the dataset by randomly mapping keys to a set of equi-sized buckets. Veil provides a tunable mechanism for data owners to explore a trade-off between storage and communication overheads. To make buckets indistinguishable to the adversary, Veil uses a novel padding strategy that allow buckets to overlap, reducing the need to add fake records. Both theoretical and experimental results show Veil to significantly outperform existing state-of-the-art.
title Hiding Access-pattern is Not Enough! Veil: A Storage and Communication Efficient Volume-Hiding Algorithm
topic Databases
Cryptography and Security
url https://arxiv.org/abs/2310.12491