Rethinking Searchable Symmetric Encryption
Symmetric Searchable Encryption (SSE) schemes enable keyword searches over encrypted documents. To obtain efficiency, SSE schemes incur a certain amount of leakage. The vast majority of the literature on SSE considers only leakage from one component of the overall SSE system, the encrypted search index. This component is used to identify which documents to return in response to a keyword query. The actual fetching of the documents is left to another component, usually left unspecified in the literature, but generally envisioned as a simple storage system matching document identifiers to encrypted documents. This raises the question: do SSE schemes actually protect the security of data and queries when considered from a system-wide viewpoint? We answer this question in the negative. We do this by introducing a new inference attack that achieves practically efficient, highly scalable, accurate query reconstruction against end-to-end SSE systems. In particular, our attack works even when
Paper 2021/879 Rethinking Searchable Symmetric Encryption Kenneth G. Paterson, ETH Zurich Sikhar Patranabis, IBM Research India Abstract Symmetric Searchable Encryption (SSE) schemes enable keyword searches over encrypted documents. To obtain efficiency, SSE schemes incur a certain amount of leakage. The vast majority of the literature on SSE considers only leakage from one component of the overall SSE system, the encrypted search index. This component is used to identify which documents to return in response to a keyword query. The actual fetching of the documents is left to another…
saved by
related reading
- Unclonable Polymers and Their Cryptographic Applicationseprint.iacr.org
- Discovering cryptographic weaknesses with Claude \ Anthropicanthropic.com
- Homomorphic encryption - Wikipediaen.wikipedia.org
- Private information retrieval using homomorphic encryption (explained from scratch)blintzbase.com
- Combining Machine Learning and Homomorphic Encryption in the Apple Ecosystem - Apple Machine Learning Researchmachinelearning.apple.com
- A High-Level Technical Overview of Fully Homomorphic Encryption || Math ∩ Programmingjeremykun.com
- Database Cryptography Fur the Rest of Us - Dhole Momentssoatok.blog
- BTX: Simple and Efficient Batch Threshold Encryptioneprint.iacr.org
- GitHub - MystenLabs/seal: Seal is a decentralized secrets management (DSM) service that relies on access control policies defined and validated on Sui.github.com
- Secure multi-party computation - Wikipediaen.wikipedia.org
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- Some thoughts about Anthropic’s new cryptanalysis resultsblog.cryptographyengineering.com