• DocumentCode
    3435630
  • Title

    Security analysis for order preserving encryption schemes

  • Author

    Xiao, Liangliang ; Yen, I-Ling

  • Author_Institution
    Univ. of Texas at Dallas, Dallas, TX, USA
  • fYear
    2012
  • fDate
    21-23 March 2012
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The development of third-party hosting, IT out-sourcing, service clouds, etc. raises important security concerns. It is safer to encrypt critical data that is hosted by a third party. However, a database must be able to process queries on the encrypted data. Many algorithms have been developed to support search query processing on encrypted data, including order preserving encryption (OPE) schemes. Security analysis plays an important role in the design of secure algorithms. It aids in understanding the level of security assured by an algorithm. Currently, security analysis of OPE schemes is limited. In [3], the authors defined an ideal OPE object and constructed an OPE scheme SEm,n that is computationally indistinguishable from the ideal object. Thus the security of the proposed OPE scheme is identical to that of the ideal OPE object. However, the security of the ideal object has not been analyzed. In this paper, we study the security of OPE schemes by analyzing the number of bits zh of the plaintext that remain secret from the adversary against a known plaintext attack with h known plaintexts. Based on the security analyses, we conclude that the ideal OPE object achieves one-wayness security, i.e., the probability for the adversary to fully recover the plaintext encrypted by the ideal OPE object against an h known plaintext attack is a negligible function of the secure parameter log m if h = o(mϵ), 0 <; ϵ <; 1, and n = m3. The results presented in the paper not only help improve our understanding of the security of OPE schemes and guide its parameter selections, but also provide a general method for analyzing their security.
  • Keywords
    cryptography; probability; query processing; IT out-sourcing; OPE schemes; critical data encryption; one-wayness security; order preserving encryption schemes; parameter selections; plaintext attack; probability; query procesing; security analysis; service clouds; third-party hosting; Databases; Encryption; Games; Random variables; Upper bound; Order preserving encryption; average min-entropy; information theory; known plaintext attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Sciences and Systems (CISS), 2012 46th Annual Conference on
  • Conference_Location
    Princeton, NJ
  • Print_ISBN
    978-1-4673-3139-5
  • Electronic_ISBN
    978-1-4673-3138-8
  • Type

    conf

  • DOI
    10.1109/CISS.2012.6310814
  • Filename
    6310814