• DocumentCode
    2730749
  • Title

    Fast, Secure Encryption for Indexing in a Column-Oriented DBMS

  • Author

    Tingjian Ge ; Zdonik, S.

  • Author_Institution
    Brown Univ., Providence, RI, USA
  • fYear
    2007
  • fDate
    15-20 April 2007
  • Firstpage
    676
  • Lastpage
    685
  • Abstract
    Networked information systems require strong security guarantees because of the new threats that they face. Various forms of encryption have been proposed to deal with this problem. In a database system, there are often two contradictory goals: security of the encryption and fast performance of queries. There have been a number of proposals of database encryption schemes to facilitate queries on encrypted columns. Order-preserving encryption techniques are well-suited for databases since they support a simple, and efficient way to build indices. However, as we will show, they are insecure under straightforward attack scenarios. We propose a new light-weight database encryption scheme (called FCE) for column stores in data warehouses with trusted servers. The low decryption overhead of FCE makes comparisons of ciphertexts and hence indexing operations very fast. Since it is hard to use classical security definitions in cryptography to prove the security of any existing symmetric encryption scheme, we propose a relaxed measure of security, called INFO-CPA-DB. INFO-CPA-DB is based on a well-established security definition in cryptography and relaxes it using information theoretic concepts. Using INFO-CPA-DB, we give strong evidence that FCE is as secure as any underlying block cipher (yet more efficient than using the block cipher itself). Using the same security measure we also show the inherent insecurity of any order preserving encryption scheme under straightforward attack scenarios. We discuss indexing techniques based on FCE as well.
  • Keywords
    cryptography; data warehouses; INFO-CPA-DB; column stores; column-oriented DBMS indexing; cryptography; data warehouses; database encryption scheme; database system; fast secure encryption; networked information systems; trusted server; Access control; Costs; Cryptography; Data security; Data warehouses; Database systems; Indexing; Information security; Information systems; Proposals;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data Engineering, 2007. ICDE 2007. IEEE 23rd International Conference on
  • Conference_Location
    Istanbul
  • Print_ISBN
    1-4244-0802-4
  • Type

    conf

  • DOI
    10.1109/ICDE.2007.367913
  • Filename
    4221716