Encrypted Databases Made Secure Yet Maintainable
Mingyu Li, Xuyang Zhao, Le Chen, Cheng Tan, Huorong Li, Sheng Wang, Zeyu Mi, Yubin Xia, Feifei Li, Haibo Chen
Abstract
State-of-the-art encrypted databases (EDBs) can be divided into two types: one that protects the whole DBMS engine in a trusted domain, and one that protects only operators that support queries over encrypted data. Both types have limitations when dealing with malicious database administrators (DBAs). The first type either exposes the data to DBAs or makes maintenance operations difficult if the DBA role is eliminated. The second type is vulnerable to abuse of the operator interfaces; in particular, we devise a smuggle attack that enables DBAs to secretly and effectively access data.
We introduce HEDB, which prevents smuggle attacks and preserves database maintainability. HEDB uses a dual-mode EDB design based on our analysis of DBA maintenance tasks. Execution Mode handles user queries by isolating DBAs from operators to prevent smuggle attacks, while Maintenance Mode enables DBMS maintenance and operator troubleshooting through authenticated replay and anonymized replay, respectively. Our evaluation shows that HEDB blocks smuggle attacks and supports common maintenance tasks with 5.88% runtime cost and 9.26% storage cost.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e21539b0-cada-4a4b-a2d7-06027f67df6bCited by top-tier papers9
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ASPLOS 2024 · 10 citations
- Object-oriented Unified Encrypted Memory Management for Heterogeneous Memory ArchitecturesMo Sha, Yifan Cai, Sheng Wang, Linh Thi Xuan Phan et al.SIGMOD 2024 · 8 citations
- TEE-based General-purpose Computational Backend for Secure Delegated Data ProcessingMo Sha, Jialin Li, Sheng Wang, Feifei Li et al.SIGMOD 2024 · 6 citations
- Principles and Methodologies for Serial Performance OptimizationSujin Park, Mingyu Guan, Xiang Cheng, Taesoo KimOSDI 2025 · 2 citations
- Jodes: Efficient Oblivious Join in the Distributed SettingYilei Wang, Xiangdong Zeng, Sheng Wang, Feifei LiVLDB 2025 · 1 citation
Builds on8
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- Generic Attacks on Secure Outsourced DatabasesGeorgios Kellaris, George Kollios, Kobbi Nissim, Adam O'NeillCCS 2016 · 327 citations
- Leakage-Abuse Attacks against Order-Revealing EncryptionPaul Grubbs, Kevin Sekniqi, Vincent Bindschaedler, Muhammad Naveed et al.S&P 2017 · 204 citations
- SoK: Cryptographically Protected Database SearchBenjamin Fuller, Mayank Varia, Arkady Yerukhimovich, Emily Shen et al.S&P 2017 · 121 citations
- Diagnosing Root Causes of Intermittent Slow Queries in Large-Scale Cloud DatabasesMinghua Ma, Zheng Yin, Shenglin Zhang, Sheng Wang et al.VLDB 2020 · 119 citations
Related papers
- Cryptanalysis of An Encrypted Database in SIGMOD '14Xinle Cao, Jian Liu, Hao Lu, Kui RenVLDB 2021 · 3 citations
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin OgierS&P 2026 · 1 citation
- SEAL: Attack Mitigation for Encrypted Databases via Adjustable LeakageIoannis Demertzis, Dimitrios Papadopoulos, Charalampos Papamanthou, Saurabh ShintreUSENIX Security 2020
- HE3DB: An Efficient and Elastic Encrypted Database Via Arithmetic-And-Logic Fully Homomorphic EncryptionSong Bian, Zhou Zhang, Haowen Pan, Ran Mao et al.CCS 2023 · 46 citations
- Encrypted Databases: New Volume Attacks against Range QueriesZichen Gui, Oliver Johnson, Bogdan WarinschiCCS 2019 · 97 citations
