RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution Time
Chen Dar, Moshik Hershcovitch, Adam Morrison
Abstract
Many modern use cases of relational databases involve multi-tenancy. To allow a tenant to only access its data, relational database systems (RDBMSs) introduced row-level security (RLS). RLS enables specifying per-row access controls, which the database enforces by rewriting tenant queries to add an RLS policy filter that filters out rows the tenant is not allowed to view. Unfortunately, while RLS blocks queries from returning unauthorized data, side-effects of query execution can form a side-channel that leaks information about such secret data.
This paper investigates how RLS query execution time can leak information about rows that the querying tenant is restricted from viewing. We show that in PostgreSQL and SQL Server, an attacker can craft indexusing queries to learn whether a value they are not authorized to view exists in an RLS-protected table, and in some cases, how many times such a value exists in the table. Our attack succeeds in a realistic cloud setting: we successfully attack managed PostgreSQL and SQL Server database instances on AWS from virtual machines in the same and different data centers.
To block the RLS time side-channel, we design a data-oblivious query scheme for the case of unique keys. We also analyze the trade-offs created by the data-oblivious approach for non-unique keys.
To facilitate the evaluation of RLS attacks and defenses, we introduce a benchmark that supports multitenancy and RLS, which are not supported by established benchmarks such as YCSB. We implement our solution in PostgreSQL and show that it achieves security with minimal performance impact.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b2a840a3-d3e9-4107-95b4-57563796594cCited by top-tier papers2
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin OgierS&P 2026 · 1 citation
- Plaintext Recovery Against Post-Filtering Access ControlZachary Espiritu, David CashUSENIX Security 2026
Builds on7
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Mitigating Leakage in Secure Cloud-Hosted Data Structures: Volume-Hiding for Multi-Maps via HashingSarvar Patel, Giuseppe Persiano, Kevin Yeo, Moti YungCCS 2019 · 139 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
- Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance ComputingJiyong Yu, Lucas Hsiung, Mohamad El Hajj, Christopher W. FletcherNDSS 2019 · 106 citations
- Structured Encryption and Dynamic Leakage SuppressionMarilyn George, Seny Kamara, Tarik MoatazEUROCRYPT 2021 · 39 citations
Related papers
- SEAL: Attack Mitigation for Encrypted Databases via Adjustable LeakageIoannis Demertzis, Dimitrios Papadopoulos, Charalampos Papamanthou, Saurabh ShintreUSENIX Security 2020
- Ohm's Law in Data Centers: A Voltage Side Channel for Timing Power AttacksMohammad A. Islam, Shaolei RenCCS 2018 · 27 citations
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel et al.MICRO 2025 · 8 citations
- Strong and Efficient Cache Side-Channel Protection using Hardware Transactional MemoryDaniel Gruss, Julian Lettner, Felix Schuster, Olga Ohrimenko et al.USENIX Security 2017 · 254 citations
- KernelSnitch: Side Channel-Attacks on Kernel Data StructuresLukas Maar, Jonas Juffinger, Thomas Steinbauer, Daniel Gruss et al.NDSS 2025
