Security Analysis of MongoDB Queryable Encryption
Zichen Gui, Kenneth G. Paterson, Tianxin Tang
摘要
In June 2022, MongoDB released Queryable Encryption (QE), an extension of their flagship database product, enabling keyword searches to be performed over encrypted data. This is the first integration of such searchable encryption technology into a widely-used database system. We provide an independent security analysis of QE. We show that certain logs, fundamental to the operation of QE and accessible to a real-world snapshot adversary, contain statistical information about the queries and data. This information can be extracted and exploited by our new inference attacks to recover both the queries and data, assuming adversarial access to an auxiliary dataset with a similar distribution to the original data. Our analysis highlights the challenges of integrating searchable encryption technology into modern, complex database systems. In particular, our attacks stem from the interplay between QE and MongoDB's existing logging system. They show how such interactions can compromise query and data privacy. Encrypted Document Collection (eDocColl) edoc3 "job": *** (219), "address": *** (24), "safeContent": (PRF F edc (1)) *** (length in bytes) ECOC Value
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Leakage-Abuse Attacks Against Forward and Backward Private Searchable Symmetric EncryptionLei Xu, Leqian Zheng, Chengzhi Xu, Xingliang Yuan 等CCS 2023 · 被引用 28 次
- SWAT: A System-Wide Approach to Tunable Leakage Mitigation in Encrypted Data StoresLeqian Zheng, Lei Xu, Cong Wang, Sheng Wang 等VLDB 2024 · 被引用 8 次
- Leakage-Abuse Attacks Against Structured Encryption for SQLAlexander Hoover, Ruth Ng, Daren Khu, Yao'an Li 等USENIX Security 2024 · 被引用 3 次
- Enabling Index-free Adjacency in Oblivious Graph Processing with Delayed DuplicationsWeiqi Feng, Xinle Cao, Adam O'Neill, Chuanhui YangVLDB 2026
- Efficient Single-Round Obfuscation of Search and Result Patterns in Searchable EncryptionTung Le, Thang HoangCCS 2026
它引用的顶会 Paper15
- Forward and Backward Private Searchable Encryption from Constrained Cryptographic PrimitivesRaphaël Bost, Brice Minaud, Olga OhrimenkoCCS 2017 · 被引用 423 次
- ∑oφoς: Forward Secure Searchable EncryptionRaphael BostCCS 2016 · 被引用 382 次
- New Constructions for Forward and Backward Private Symmetric Searchable EncryptionJavad Ghareh Chamani, Dimitrios Papadopoulos, Charalampos Papamanthou, Rasool JaliliCCS 2018 · 被引用 242 次
- Pump up the Volume: Practical Database Reconstruction from Volume Leakage on Range QueriesPaul Grubbs, Marie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonCCS 2018 · 被引用 172 次
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 被引用 152 次
相关 Paper
- Rethinking Searchable Symmetric EncryptionZichen Gui, Kenneth G. Paterson, Sikhar PatranabisS&P 2023
- LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetJianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan 等CCS 2021 · 被引用 32 次
- Leakage Inversion: Towards Quantifying Privacy in Searchable EncryptionEvgenios M. Kornaropoulos, Nathaniel Moyer, Charalampos Papamanthou, Alexandros PsomasCCS 2022 · 被引用 26 次
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 被引用 46 次
- Your Keywords Know Each Other: Breaking SSE with <1% Leaked DocumentsMingyu Bian, Jiabei Wang, Dandan Xu, Guangyu Huang 等USENIX Security 2026
