首页> 外文会议>IEEE Conference on Communications and Network Security >Secure and Efficient Multi-Attribute Range Queries based on Comparable Inner Product Encoding
【24h】

Secure and Efficient Multi-Attribute Range Queries based on Comparable Inner Product Encoding

机译:基于可比内部产品编码的安全有效的多属性范围查询

获取原文
获取外文期刊封面目录资料

摘要

Encryption, a powerful tool for data security, has been widely applied to protect sensitive data stored on untrusted cloud servers. One important problem in such an environment is how to support advanced query predicates, such as range queries, over an encrypted data set in an efficient and secure way. Order-preserving encryption (OPE) produces ciphertexts that preserve the order of their plaintexts and performs range queries directly on ciphertexts. However, ideally secure OPE schemes are inefficient (interactive and stateful), because they either ask for extensive client-to-server interactions or require a large persistent client storage that relates to the size of the data set. In this paper, we propose a comparable inner product encoding (CIPE) scheme to support multi-attribute range queries over encrypted data. Our main idea is to encode data and query values as encrypted vectors so that order comparison is realized by calculating the vector's inner product. Compared with existing OPE schemes, our scheme has the following merits: 1) High $e$ ficiency. It allows a client to retrieve data of interest in one round without maintaining any local state. 2) Enhanced security. It achieves ideal security while effectively resisting inference attacks that existing OPE schemes are vulnerable to. Extensive experiments conducted on a real- world, large-scale data set verify the effectiveness of our scheme.
机译:加密是一种用于数据安全的强大工具,已被广泛应用于保护存储在不受信任的云服务器上的敏感数据。这种环境中的一个重要问题是如何以高效且安全的方式通过加密数据集支持高级查询谓词,例如范围查询。订单保留加密(ope)生成密文,该密文保留其明文的顺序,并直接在密文上执行范围查询。然而,理想的安全OPE方案效率低下(交互和状态),因为他们要么要求广泛的客户端到服务器交互,要么需要与数据集的大小相关的大型持久性客户端存储。在本文中,我们提出了一种可比较的内部产品编码(CIPE)方案来支持通过加密数据的多属性范围查询。我们的主要思想是将数据和查询值编码为加密向量,以便通过计算向量的内部产品来实现订单比较。与现有OPE方案相比,我们的计划具有以下优点:1)高额$ E $效率。它允许客户端在一轮中检索感兴趣的数据而不保持任何本地状态。 2)增强安全性。它实现了理想的安全性,同时有效地抵制了现有OPE方案容易受到伤害的推动攻击。在现实世界中进行的广泛实验,大规模数据集验证了我们计划的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号