首页> 外文会议>IEEE Conference on Communications and Network Security >Secure and Efficient Multi-Attribute Range Queries based on Comparable Inner Product Encoding
【24h】

Secure and Efficient Multi-Attribute Range Queries based on Comparable Inner Product Encoding

机译:基于可比的内部产品编码的安全高效的多属性范围查询

获取原文

摘要

Encryption, a powerful tool for data security, has been widely applied to protect sensitive data stored on untrusted cloud servers. One important problem in such an environment is how to support advanced query predicates, such as range queries, over an encrypted data set in an efficient and secure way. Order-preserving encryption (OPE) produces ciphertexts that preserve the order of their plaintexts and performs range queries directly on ciphertexts. However, ideally secure OPE schemes are inefficient (interactive and stateful), because they either ask for extensive client-to-server interactions or require a large persistent client storage that relates to the size of the data set. In this paper, we propose a comparable inner product encoding (CIPE) scheme to support multi-attribute range queries over encrypted data. Our main idea is to encode data and query values as encrypted vectors so that order comparison is realized by calculating the vector's inner product. Compared with existing OPE schemes, our scheme has the following merits: 1) High $e$ ficiency. It allows a client to retrieve data of interest in one round without maintaining any local state. 2) Enhanced security. It achieves ideal security while effectively resisting inference attacks that existing OPE schemes are vulnerable to. Extensive experiments conducted on a real- world, large-scale data set verify the effectiveness of our scheme.
机译:加密是一种强大的数据安全工具,已广泛应用于保护存储在不受信任的云服务器上的敏感数据。在这种环境中的一个重要问题是如何以有效和安全的方式在加密的数据集上支持高级查询谓词(例如范围查询)。保序加密(OPE)生成的密文将保留其明文的顺序,并直接对密文执行范围查询。但是,理想的安全OPE方案效率低下(交互式和有状态),因为它们要么要求进行大量的客户端到服务器交互,要么需要与数据集大小相关的大型持久性客户端存储。在本文中,我们提出了一种可比较的内积编码(CIPE)方案,以支持对加密数据进行多属性范围查询。我们的主要思想是将数据和查询值编码为加密的向量,以便通过计算向量的内积来实现顺序比较。与现有的OPE计划相比,我们的计划具有以下优点:1)高e $ e $效率。它允许客户端在不保持任何本地状态的情况下,在一轮中检索感兴趣的数据。 2)增强的安全性。它可以实现理想的安全性,同时可以有效抵抗现有OPE方案容易受到的推理攻击。在真实的大规模数据集上进行的大量实验证明了我们方案的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号