• DocumentCode
    612050
  • Title

    An Ideal-Security Protocol for Order-Preserving Encoding

  • Author

    Popa, R.A. ; Li, F.H. ; Zeldovich, Nickolai

  • fYear
    2013
  • fDate
    19-22 May 2013
  • Firstpage
    463
  • Lastpage
    477
  • Abstract
    Order-preserving encryption - an encryption scheme where the sort order of ciphertexts matches the sort order of the corresponding plaintexts - allows databases and other applications to process queries involving order over encrypted data efficiently. The ideal security guarantee for order-preserving encryption put forth in the literature is for the ciphertexts to reveal no information about the plaintexts besides order. Even though more than a dozen schemes were proposed, all these schemes leak more information than order. This paper presents the first order-preserving scheme that achieves ideal security. Our main technique is mutable ciphertexts, meaning that over time, the ciphertexts for a small number of plaintext values change, and we prove that mutable ciphertexts are needed for ideal security. Our resulting protocol is interactive, with a small number of interactions. We implemented our scheme and evaluated it on microbenchmarks and in the context of an encrypted MySQL database application. We show that in addition to providing ideal security, our scheme achieves 1 - 2 orders of magnitude higher performance than the state-of-the-art order-preserving encryption scheme, which is less secure than our scheme.
  • Keywords
    SQL; cryptographic protocols; encoding; query processing; encrypted MySQL database application; first order-preserving scheme; ideal-security protocol; microbenchmarks; mutable ciphertexts; order-preserving encoding; order-preserving encryption; plaintexts; query processing; Encoding; Encryption; Protocols; Servers; Vegetation; encoding; order-preserving encryption;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2013 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-1-4673-6166-8
  • Electronic_ISBN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2013.38
  • Filename
    6547127