USENIX Security2026Top-tier venue
Plaintext Recovery Against Post-Filtering Access Control
Zachary Espiritu, David Cash
Abstract
Fine-grained access control (FGAC) mechanisms such as row-level security (RLS) and document-level security (DLS) are widely deployed in databases to restrict access to data stored in physical indexing structures shared by multiple users (e.g., in multi-tenant databases, or in the implementation of least-privilege within an organization). FGAC implementations often use post-filtering where untrusted queries run over all data and private results are redacted afterwards. Prior work shows this approach can lead to side-channels that enable attackers to test if a chosen value exists in unseen data. While damaging, prior attacks do not enable the efficient recovery of rich, high-entropy data like full records or text documents. We show these side-channels are more damaging than previously thought. Using rich query interfaces (e.g., range, prefix, and conjunctive predicates), we amplify existence leakage into reconstruction attacks. We do this in two settings: PostgreSQL (RLS timing). We exploit a timing side-channel and expressive SQL queries (e.g., ranges, conjunctions) to enumerate unknown attribute values and, in turn, full records via binary search over large domains. Elasticsearch/OpenSearch (DLS scoring). We exploit scoring and prefix-expansion side-channels to recover indexed terms from documents. In some cases, we can extract n-grams in the corpus to recover approximate text. Our results show that FGAC side-channels must be evaluated in the presence of rich predicates, which can turn membership tests into scalable reconstruction of high-entropy records.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cf4b7322-4dc5-4b4d-8e59-bdaff2e97a50Builds on17
- Generic Attacks on Secure Outsourced DatabasesGeorgios Kellaris, George Kollios, Kobbi Nissim, Adam O'NeillCCS 2016 · 327 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Improved Reconstruction Attacks on Encrypted Data Using Range Query LeakageMarie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonS&P 2018 · 183 citations
- Full Database Reconstruction in Two DimensionsFrancesca Falzon, Evangelia Anna Markatou, Akshima, David Cash et al.CCS 2020 · 27 citations
- Database Reconstruction from Noisy Volumes: A Cache Side-Channel Attack on SQLiteAria Shahverdi, Mahammad Shirinov, Dana Dachman-SoledUSENIX Security 2021 · 20 citations
Related papers
- RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution TimeChen Dar, Moshik Hershcovitch, Adam MorrisonSIGMOD 2023 · 6 citations
- Forward and Backward Private Conjunctive Searchable Symmetric EncryptionSikhar Patranabis, Debdeep MukhopadhyayNDSS 2021
- Reconstructing with Less: Leakage Abuse Attacks in Two DimensionsEvangelia Anna Markatou, Francesca Falzon, Roberto Tamassia, William SchorCCS 2021 · 22 citations
- Side-Channel Attacks on Shared Search IndexesLiang Wang, Paul Grubbs, Jiahui Lu, Vincent Bindschaedler et al.S&P 2017 · 9 citations
- Leakage-Abuse Attacks Against Structured Encryption for SQLAlexander Hoover, Ruth Ng, Daren Khu, Yao'an Li et al.USENIX Security 2024 · 3 citations
