USENIX Security2023Top-tier venue
High Recovery with Fewer Injections: Practical Binary Volumetric Injection Attacks against Dynamic Searchable Encryption
Xianglong Zhang, Wei Wang, Peng Xu, Laurence T. Yang, Kaitai Liang
Abstract
Searchable symmetric encryption enables private queries over an encrypted database, but it also yields information leakages. Adversaries can exploit these leakages to launch injection attacks (Zhang et al., USENIX'16) to recover the underlying keywords from queries. The performance of the existing injection attacks is strongly dependent on the amount of leaked information or injection. In this work, we propose two new injection attacks, namely BVA and BVMA, by leveraging a binary volumetric approach. We enable adversaries to inject fewer files than the existing volumetric attacks by using the known keywords and reveal the queries by observing the volume of the query results. Our attacks can thwart well-studied defenses (e.g., threshold countermeasure, static padding) without exploiting the distribution of target queries and client databases. We evaluate the proposed attacks empirically in real-world datasets with practical queries. The results show that our attacks can obtain a high recovery rate (>80%) in the best case and a roughly 60% recovery even under a large-scale dataset with a small number of injections (<20 files).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fc6383b6-4cd8-4ab1-8ab5-56d3f5928682Cited by top-tier papers7
- Leakage-Abuse Attacks Against Forward and Backward Private Searchable Symmetric EncryptionLei Xu, Leqian Zheng, Chengzhi Xu, Xingliang Yuan et al.CCS 2023 · 28 citations
- MUSES: Efficient Multi-User Searchable Encrypted DatabaseTung Le, Rouzbeh Behnia, Jorge Guajardo, Thang HoangUSENIX Security 2024 · 11 citations
- d-DSE: Distinct Dynamic Searchable Encryption Resisting Volume Leakage in Encrypted DatabasesDongli Liu, Wei Wang, Peng Xu, Laurence T. Yang et al.USENIX Security 2024 · 11 citations
- Learning from Leakage: Database Reconstruction from Just a Few Multidimensional Range QueriesPeijie Li, Huanhuan Chen, Kaitai Liang, Evangelia Anna MarkatouNDSS 2026 · 1 citation
- Mitigating Injection Attacks against E2EE Applications via View-Based PartitioningAndrés Fábrega, Samuel Breckenridge, Armin Namavari, Thomas RistenpartUSENIX Security 2025
Builds on16
- All Your Queries Are Belong to Us: The Power of File-Injection Attacks on Searchable EncryptionYupeng Zhang, Jonathan Katz, Charalampos PapamanthouUSENIX Security 2016 · 512 citations
- Forward and Backward Private Searchable Encryption from Constrained Cryptographic PrimitivesRaphaël Bost, Brice Minaud, Olga OhrimenkoCCS 2017 · 423 citations
- Result Pattern Hiding Searchable Encryption for Conjunctive QueriesShangqi Lai, Sikhar Patranabis, Amin Sakzad, Joseph K. Liu et al.CCS 2018 · 216 citations
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 152 citations
- Mitigating Leakage in Secure Cloud-Hosted Data Structures: Volume-Hiding for Multi-Maps via HashingSarvar Patel, Giuseppe Persiano, Kevin Yeo, Moti YungCCS 2019 · 139 citations
Related papers
- Query Recovery from Easy to Hard: Jigsaw Attack against SSEHao Nie, Wei Wang, Peng Xu, Xianglong Zhang et al.USENIX Security 2024 · 13 citations
- Revisiting Leakage Abuse AttacksLaura Blackstone, Seny Kamara, Tarik MoatazNDSS 2020
- ∑oφoς: Forward Secure Searchable EncryptionRaphael BostCCS 2016 · 382 citations
- Pump up the Volume: Practical Database Reconstruction from Volume Leakage on Range QueriesPaul Grubbs, Marie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonCCS 2018 · 172 citations
- Rethinking Searchable Symmetric EncryptionZichen Gui, Kenneth G. Paterson, Sikhar PatranabisS&P 2023
