Privacy-preserving Searchable Databases with Controllable Leakage
Shujie Cui, Xiangfu Song, Muhammad Rizwan Asghar, Steven D Galbraith,, and Giovanni Russello

TL;DR
This paper introduces P-McDb, a privacy-preserving searchable encryption scheme that minimizes data leakage, protects against inference attacks, and maintains efficiency, enabling secure multi-cloud database searches.
Contribution
It proposes a novel multi-cloud symmetric searchable encryption scheme with minimal leakage, forward/backward privacy, and resistance to inference and injection attacks.
Findings
P-McDb effectively reduces leakage and protects search patterns.
The scheme resists active injection and inference attacks.
Prototype implementation demonstrates practical efficiency.
Abstract
Searchable Encryption (SE) is a technique that allows Cloud Service Providers (CSPs) to search over encrypted datasets without learning the content of queries and records. In recent years, many SE schemes have been proposed to protect outsourced data from CSPs. Unfortunately, most of them leak sensitive information, from which the CSPs could still infer the content of queries and records by mounting leakage-based inference attacks, such as the count attack and file injection attack. In this work, first we define the leakage in searchable encrypted databases and analyse how the leakage is leveraged in existing leakage-based attacks. Second, we propose a Privacy-preserving Multi-cloud based dynamic symmetric SE (SSE) scheme for relational Database (P-McDb). P-McDb has minimal leakage, which not only ensures confidentiality of queries and records, but also protects the search, access,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Privacy-Preserving Technologies in Data · Cloud Data Security Solutions
