SAGMA: Secure Aggregation Grouped by Multiple Attributes
Timon Hackenjos, Florian Hahn, Florian Kerschbaum
Abstract
Encryption can protect data in outsourced databases -in the cloud -while still enabling query processing over the encrypted data. However, the processing leaks information about the data specific to the type of query, e.g., aggregation queries. Aggregation over user-defined groups using SQL's GROUP BY clause is extensively used in data analytics, e.g., to calculate the total number of visitors each month or the average salary in each department. The information leaked, e.g., the access pattern to a group, may reveal the group's frequency enabling simple, yet detrimental leakage-abuse attacks.
In this work we present SAGMA -an encryption scheme for performing secure aggregation grouped by multiple attributes. The querier can choose any combination of one or multiple attributes in the GROUP BY clause among the set of all grouping attributes. The encryption scheme only stores semantically secure ciphertexts at the cloud and query processing hides the access pattern, i.e., the frequency of each group. We implemented our scheme and our evaluation results underpin its practical feasibility.
• Security and privacy → Management and querying of encrypted data; Privacy-preserving protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2e03afad-258c-47f5-ba51-99a5eb1e3fdaCited by top-tier papers3
- HEDA: Multi-Attribute Unbounded Aggregation over Homomorphically Encrypted DatabaseXuanle Ren, Le Su, Zhen Gu, Sheng Wang et al.VLDB 2023 · 42 citations
- HEIR: A Unified Representation for Cross-Scheme Compilation of Fully Homomorphic ComputationSong Bian, Zian Zhao, Zhou Zhang, Ran Mao et al.NDSS 2024
- Engorgio: An Arbitrary-Precision Unbounded-Size Hybrid Encrypted Database via Quantized Fully Homomorphic EncryptionSong Bian, Haowen Pan, Jiaqi Hu, Zhou Zhang et al.USENIX Security 2025
Builds on4
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Leakage-Abuse Attacks against Order-Revealing EncryptionPaul Grubbs, Kevin Sekniqi, Vincent Bindschaedler, Muhammad Naveed et al.S&P 2017 · 204 citations
- SoK: Cryptographically Protected Database SearchBenjamin Fuller, Mayank Varia, Arkady Yerukhimovich, Emily Shen et al.S&P 2017 · 121 citations
- Secure Search on Encrypted Data via Multi-Ring SketchAdi Akavia, Dan Feldman, Hayim ShaulCCS 2018 · 32 citations
Related papers
- Equi-Joins over Encrypted Data for Series of QueriesMasoumeh Shafieinejad, Suraj Gupta, Jin Yang Liu, Koray Karabina et al.ICDE 2022 · 14 citations
- Privacy Preserving Strong Simulation Queries on Large GraphsLyu Xu, Jiaxin Jiang, Byron Choi, Jianliang Xu et al.ICDE 2021 · 18 citations
- Differentially Private Access in Encrypted Search: Achieving Privacy at a Small Cost?Daniel Pöllmann, Tianxin TangCCS 2025
- SEAL: Attack Mitigation for Encrypted Databases via Adjustable LeakageIoannis Demertzis, Dimitrios Papadopoulos, Charalampos Papamanthou, Saurabh ShintreUSENIX Security 2020
- Obfuscated Access and Search Patterns in Searchable EncryptionZhiwei Shang, Simon Oya, Andreas Peter, Florian KerschbaumNDSS 2021
