Visible to the public What Else is Revealed by Order-Revealing Encryption?

TitleWhat Else is Revealed by Order-Revealing Encryption?
Publication TypeConference Paper
Year of Publication2016
AuthorsDurak, F. Betül, DuBuisson, Thomas M., Cash, David
Conference NameProceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
Date PublishedOctober 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4139-4
Keywordsaudits, compositionality, database encryption, Encryption, encryption audits, inference attacks, Metrics, order-revealing encryption, pubcrawl, resilience
Abstract

The security of order-revealing encryption (ORE) has been unclear since its invention. Dataset characteristics for which ORE is especially insecure have been identified, such as small message spaces and low-entropy distributions. On the other hand, properties like one-wayness on uniformly-distributed datasets have been proved for ORE constructions. This work shows that more plaintext information can be extracted from ORE ciphertexts than was previously thought. We identify two issues: First, we show that when multiple columns of correlated data are encrypted with ORE, attacks can use the encrypted columns together to reveal more information than prior attacks could extract from the columns individually. Second, we apply known attacks, and develop new attacks, to show that the leakage of concrete ORE schemes on non-uniform data leads to more accurate plaintext recovery than is suggested by the security theorems which only dealt with uniform inputs.

URLhttps://dl.acm.org/doi/10.1145/2976749.2978379
DOI10.1145/2976749.2978379
Citation Keydurak_what_2016