首页> 外文期刊>Journal of computer security >A multi-server oblivious dynamic searchable encryption framework
【24h】

A multi-server oblivious dynamic searchable encryption framework

机译:多服务器遗忘的动态可搜索加密框架

获取原文
获取原文并翻译 | 示例

摘要

Data privacy is one of the main concerns for data outsourcing on the cloud. Although standard encryption can provide confidentiality, it prevents the client from searching/retrieving meaningful information on the outsourced data thereby, degrading the benefits of using cloud services. To address this data utilization versus privacy dilemma, Dynamic Searchable Symmetric Encryption (DSSE) has been proposed. DSSE enables encrypted search and update functionality over the encrypted data via a secure index. However, the state-of-the-art DSSE constructions leak information from the access pattern, making them vulnerable against various attacks. While generic Oblivious Random Access Machine (ORAM) can hide the access pattern, it incurs a heavy communication overhead, which was shown costly to be directly used in the DSSE setting. In this article, by exploiting the multi-cloud infrastructure, we develop a comprehensive Oblivious Distributed DSSE (ODSE) framework that allows oblivious search and updates on the encrypted index with high security and improved efficiency over the use of generic ORAM. Our framework contains a series of ODSE schemes each featuring different levels of performance and security required by various types of real-life applications. ODSE offers desirable security guarantees such as information-theoretic security and robustness in the presence of a malicious adversary. We fully implemented ODSE framework and evaluated its performance in a real cloud environment (Amazon EC2). Our experiments showed that ODSE schemes are 3 × -57 × faster than using generic ORAMs on a DSSE encrypted index under real network settings.
机译:数据隐私是云上数据外包的主要问题之一。尽管标准加密可以提供机密性,但是它阻止客户端在外包数据上搜索/检索有意义的信息,从而降低了使用云服务的好处。为了解决这种数据利用与隐私困境的矛盾,提出了动态可搜索对称加密(DSSE)。 DSSE通过安全索引对加密数据启用加密搜索和更新功能。但是,最新的DSSE构造会从访问模式中泄漏信息,从而使其容易受到各种攻击。尽管通用的遗忘随机访问机器(ORAM)可以隐藏访问模式,但它会带来大量的通信开销,这表明直接在DSSE设置中使用该开销很大。在本文中,通过利用多云基础架构,我们开发了一个全面的Oblivious Distributed DSSE(ODSE)框架,该框架允许在加密索引上进行隐式搜索和更新,与使用普通ORAM相比,具有更高的安全性和更高的效率。我们的框架包含一系列ODSE方案,每个方案都具有各种类型的实际应用程序所需的不同级别的性能和安全性。 ODSE提供了理想的安全保证,例如在存在恶意对手的情况下的信息理论安全性和鲁棒性。我们完全实施了ODSE框架并评估了它在真实云环境(Amazon EC2)中的性能。我们的实验表明,在实际网络设置下,ODSE方案比在DSSE加密索引上使用通用ORAM的速度快3×-57×。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号