Revisiting Frequency Analysis against Encrypted Deduplication via Statistical Distribution
Jingwei Li, Guoli Wei, Jiacheng Liang, Yanjing Ren, Patrick P. C. Lee, Xiaosong Zhang
Abstract
Encrypted deduplication addresses both security and storage efficiency in large-scale storage systems: it ensures that each plaintext is encrypted to a ciphertext by a symmetric key derived from the content of the plaintext, so as to allow deduplication on the ciphertexts derived from duplicate plaintexts. However, the deterministic nature of encrypted deduplication leaks the frequencies of plaintexts, thereby allowing adversaries to launch frequency analysis against encrypted deduplication and infer the ciphertext-plaintext pairs in storage. In this paper, we revisit the security vulnerability of encrypted deduplication due to frequency analysis, and show that encrypted deduplication can be even more vulnerable to the sophisticated frequency analysis attack that exploits the underlying storage workload characteristics. We propose the distribution-based attack, which builds on a statistical approach to model the relative frequency distributions of plaintexts and ciphertexts, and improves the inference precision (i.e., have high confidence on the correctness of inferred ciphertext-plaintext pairs) of the previous attack. We evaluate the new attack against real-world storage workloads and provide insights into its actual damage.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ed45356e-e3e5-4220-b37a-daf58345d531Cited by top-tier papers2
- SimEnc: A High-Performance Similarity-Preserving Encryption Approach for Deduplication of Encrypted Docker ImagesTong Sun, Bowen Jiang, Borui Li, Jiamei Lv et al.USENIX ATC 2024 · 10 citations
- FeatureSpy: Detecting Learning-Content Attacks via Feature Inspection in Secure Deduplicated StorageJingwei Li, Yanjing Ren, Patrick P. C. Lee, Yuyu Wang et al.INFOCOM 2023 · 7 citations
Related papers
- Balancing storage efficiency and data confidentiality with tunable encrypted deduplicationJingwei Li, Zuoru Yang, Yanjing Ren, Patrick P. C. Lee et al.EuroSys 2020 · 46 citations
- Frequency-revealing attacks against Frequency-hiding Order-preserving EncryptionXinle Cao, Jian Liu, Yongsheng Shen, Xiaohua Ye et al.VLDB 2023 · 9 citations
- Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-EncryptionZuoru Yang, Jingwei Li, Patrick P. C. LeeUSENIX ATC 2022 · 46 citations
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 46 citations
- Leakage-Abuse Attacks Against Forward and Backward Private Searchable Symmetric EncryptionLei Xu, Leqian Zheng, Chengzhi Xu, Xingliang Yuan et al.CCS 2023 · 28 citations
