Oblivious Dynamic Searchable Encryption on Distributed Cloud Systems

Dynamic Searchable Symmetric Encryption (DSSE) allows search/update operations over encrypted data via an encrypted index. However, DSSE has been shown to be vulnerable to statistical inference attacks, which can extract a significant amount of information from access patterns on encrypted index and files. While generic Oblivious Random Access Machine (ORAM) can hide access patterns, it has been shown to be extremely costly to be directly used in DSSE setting. By exploiting the distributed cloud infrastructure, we develop a series of Oblivious Distributed DSSE schemes called ODSE, which enable oblivious access on the encrypted index with a high security and improved efficiency over the use of generic ORAM. Specifically, ODSE schemes are 3x-57x faster than applying the state-of-the-art generic ORAMs on encrypted dictionary index in real network settings. One of the proposed ODSE schemes offers desirable security guarantees such as information-theoretic security with robustness against malicious servers. These properties are achieved by exploiting some of the unique characteristics of searchable encryption and encrypted index, which permits us to harness the computation and communication efficiency of multi-server PIR and Write-Only ORAM simultaneously. We fully implemented ODSE and have conducted extensive experiments to assess the performance of our proposed schemes in a real cloud environment.


Published in:
Data and Applications Security and Privacy Xxxii, Dbsec 2018, 10980, 113-130
Presented at:
32nd Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy (DBSec), Bergamo, Italy, July 16-18, 2018
Year:
Jan 01 2018
Publisher:
Cham, SPRINGER INTERNATIONAL PUBLISHING AG
ISSN:
0302-9743
1611-3349
ISBN:
978-3-319-95729-6
978-3-319-95728-9
Keywords:
Laboratories:




 Record created 2019-10-24, last modified 2019-12-05


Rate this document:

Rate this document:
1
2
3
 
(Not yet reviewed)