HybrIDX: New Hybrid Index for Volume-hiding Range Queries in Data Outsourcing Services

2020 IEEE 40th International Conference on Distributed Computing Systems (ICDCS)(2020)

引用 19|浏览30
暂无评分
摘要
An encrypted index is a data structure that assisting untrusted servers to provide various query functionalities in the ciphertext domain. Although traditional index designs can prevent servers from directly obtaining plaintexts, the confidentiality of outsourced data could still be compromised by observing the volume of different queries. Recent volume attacks have demonstrated the importance of sealing volume-pattern leakage. To this end, several works are made to design secure indexes with the volume-hiding property. However, prior designs only work for encrypted keyword search. Due to the unpredictable range query results, it is difficult to protect the volume-pattern leakage while achieving efficient range queries. In this paper, for the first time, we define and solve the challenging problem of volume-hiding range queries over encrypted data. Our proposed hybrid index framework, called HybrIDX, allows an untrusted server to efficiently search encrypted data based on order conditions without revealing the exact volume size. It resorts to the trusted hardware techniques to assist range query processing by moving the comparison algorithm to trusted SGX enclaves. To enable volume-hiding data retrieval, we propose to host encrypted results outside the enclave in an encrypted multimaps manner. Apart from this novel hybrid index design, we further customize a bulk refresh mechanism to enable accesspattern obfuscation. We formally analyze the security strengths and complete the prototype implementation. Evaluation results demonstrate the feasibility and practicability of our designs.
更多
查看译文
关键词
volume-hiding range queries,data outsourcing services,encrypted index,data structure,untrusted server,query functionalities,outsourced data,volume-pattern leakage,secure indexes,volume-hiding property,encrypted keyword search,unpredictable range query results,encrypted data,hybrid index framework,query processing,volume-hiding data retrieval,encrypted multimaps manner,hybrid index design,ciphertext domain
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要