USENIX Security2024Top-tier venue
Query Recovery from Easy to Hard: Jigsaw Attack against SSE
Hao Nie, Wei Wang, Peng Xu, Xianglong Zhang, Laurence T. Yang, Kaitai Liang
Abstract
Searchable symmetric encryption schemes often unintentionally disclose certain sensitive information, such as access, volume, and search patterns. Attackers can exploit such leakages and other available knowledge related to the user's database to recover queries. We find that the effectiveness of query recovery attacks depends on the volume/frequency distribution of keywords. Queries containing keywords with high volumes/frequencies are more susceptible to recovery, even when countermeasures are implemented. Attackers can also effectively leverage these ``special'' queries to recover all others. By exploiting the above finding, we propose a Jigsaw attack that begins by accurately identifying and recovering those distinctive queries. Leveraging the volume, frequency, and co-occurrence information, our attack achieves accuracy in three tested datasets, which is comparable to previous attacks (Oya et al., USENIX' 22 and Damie et al., USENIX' 21). With the same runtime, our attack demonstrates an advantage over the attack proposed by Oya et al (approximately more accuracy when the keyword universe size is 15k). Furthermore, our proposed attack outperforms existing attacks against widely studied countermeasures, achieving roughly and accuracy against the padding and the obfuscation, respectively. In this context, with a large keyword universe (3k), it surpasses current state-of-the-art attacks by more than .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext febb1573-3801-4054-807b-ff8f975b393aCited by top-tier papers7
- LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetJianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan et al.CCS 2021 · 32 citations
- Learning from Leakage: Database Reconstruction from Just a Few Multidimensional Range QueriesPeijie Li, Huanhuan Chen, Kaitai Liang, Evangelia Anna MarkatouNDSS 2026 · 1 citation
- ALERT: Machine Learning-Enhanced Risk Estimation for Databases Supporting Encrypted QueriesLongxiang Wang, Lei Xu, Yufei Chen, Ying Zou et al.USENIX Security 2025
- Your Keywords Know Each Other: Breaking SSE with <1% Leaked DocumentsMingyu Bian, Jiabei Wang, Dandan Xu, Guangyu Huang et al.USENIX Security 2026
- DDR-SSE: Duplicated Retrieval of Documents for System-wide Secure Searchable Symmetric EncryptionZichen Gui, Simon-Philipp Merz, Kenneth G. Paterson, Sikhar PatranabisUSENIX Security 2026
Builds on14
- Forward and Backward Private Searchable Encryption from Constrained Cryptographic PrimitivesRaphaël Bost, Brice Minaud, Olga OhrimenkoCCS 2017 · 423 citations
- ∑oφoς: Forward Secure Searchable EncryptionRaphael BostCCS 2016 · 382 citations
- New Constructions for Forward and Backward Private Symmetric Searchable EncryptionJavad Ghareh Chamani, Dimitrios Papadopoulos, Charalampos Papamanthou, Rasool JaliliCCS 2018 · 242 citations
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 152 citations
- The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable EncryptionDavid Pouliot, Charles V. WrightCCS 2016 · 132 citations
Related papers
- High Recovery with Fewer Injections: Practical Binary Volumetric Injection Attacks against Dynamic Searchable EncryptionXianglong Zhang, Wei Wang, Peng Xu, Laurence T. Yang et al.USENIX Security 2023
- Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent ObservationsHao Nie, Wei Wang, Peng Xu, Wei Chen et al.CCS 2025
- IHOP: Improved Statistical Query Recovery against Searchable Symmetric Encryption through Quadratic OptimizationSimon Oya, Florian KerschbaumUSENIX Security 2022
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 46 citations
- Encrypted Databases: New Volume Attacks against Range QueriesZichen Gui, Oliver Johnson, Bogdan WarinschiCCS 2019 · 97 citations
