A Formal Information-Theoretic Leakage Analysis of Order-Revealing Encryption - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

A Formal Information-Theoretic Leakage Analysis of Order-Revealing Encryption

Résumé

Order-Revealing Encryption (ORE) allows deriving the order of two plaintexts to facilitate database functions such as range queries and sorting. Ideally, nothing is observable to an adversary beyond the order of the messages. Unfortunately, Ideal ORE is challenging to implement, and a variation of it has then been developed. This variation, referred to as CLWW ORE, reveals the first differing bit position between every two plaintexts, in addition to the order. We provide a formal leakage analysis of these two ORE variations by applying the information-theoretic quantitative information flow (QIF) framework. We evaluate two threat models: (1) the Bayes scenario in which an adversary wishes to guess the secret entirely and (2) a bucketing scenario in which an adversary is content to simply guess the range of the plaintext. We provide security implications, usage guidelines, and a mitigation technique that improves the security of Ideal ORE. We find that while Ideal and CLWW ORE perform similarly under the Bayes scenario, CLWW ORE is fundamentally insecure under the bucketing scenario.
Fichier principal
Vignette du fichier
Order Revealing Encryption.pdf (1.03 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03906677 , version 1 (19-12-2022)

Identifiants

Citer

Mireya Jurado, Catuscia Palamidessi, Geoffrey Smith. A Formal Information-Theoretic Leakage Analysis of Order-Revealing Encryption. 2021 IEEE 34th Computer Security Foundations Symposium (CSF), Jun 2021, Dubrovnik, France. pp.1-16, ⟨10.1109/CSF51468.2021.00046⟩. ⟨hal-03906677⟩
32 Consultations
58 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More