Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
Multi-Dimensional Range Query
over Encrypted Data
Authors: Elaine Shi, Joint work with John Bethencourt, Hubert Chan, Dawn Song, Adrian Perrig
Slides originated from Elaine Shi, modified by Michael Chen
CSC 774 Advanced Network Security
Instructor: Dr. Peng Ning
Presenter: Michael Chen
April 19, 2007
Motivation - Network Audit Logs
Network gateway
Data center
Speaking Requirement Talk
2
An Ideal Solution
Network gateway
Data center
Speaking Requirement Talk
3
Auditor
Query:
(100 · port · 200) Æ ( ip 2 128.1.*.* )
auditor
Speaking Requirement Talk
Trusted
authority
4
Auditor
Query:
(100 · port · 200) Æ ( ip 2 128.1.*.* )
auditor
Speaking Requirement Talk
Capability:
(100 · port · 200) Æ ( ip 2 128.1.*.* ) Trusted
authority
5
Security
Query:
(100 · port · 200) Æ (ip 2 128.1.*.*)
• Can decrypt all matching entries
• Cannot learn additional information for
non-matching entries
– Except for the fact that they do not match
Speaking Requirement Talk
6
The Challenges
• Current practices:
– No encryption
– All-or-nothing decryption
• Challenge:
– How to design such an encryption scheme
– Efficiency
– Security
Speaking Requirement Talk
7
Related work
• Search on encrypted data (SoE)
– Not clear if can be extended to range query
over multiple attributes.
• Anonymous hierarchical IBE (AHIBE)
– Could be used to implement MRQED,
encryption cost O(TD)
• Concurrent work
– BonehWaters06: Complex query over
encrypted data. More expensive public key
size, encryption cost, cheaper decryption
cost and shorter decryption key size.
Speaking Requirement Talk
8
Generalized Problem Definition
• Time-stamp t, source address a, destination
port p
• A tuple (t, a, p) can be viewed as a point x in
3 dimensional space.
• Query for flows with t [t1 , t2 ], a [a1 , a2 ], p [ p1 , p2 ]
• Hyper-rectangle B in space
[t1 , t2 ] [a1 , a2 ] [ p1 , p2 ]
• x is in B ?
Speaking Requirement Talk
9
Generalized Problem Definition
• KeyGen
– Key generation
• Encrypt
– Encryption
• DeriveKey
– Compute a decryption key
• QueryDecrypt
– Attempt to decrypt using a capability
Speaking Requirement Talk
10
KeyGen (, n)
• Input
– k: security parameter
– n: bit-length of x
KeyGen(, n)
• Output
– public key PK & master
private key SK
Speaking Requirement Talk
Trusted authority
11
Encrypt(PK, x, msg)
x – a point
Cipher_Text à Encrypt(PK, x, msg)
Speaking Requirement Talk
12
DeriveKey(PK, SK, B )
DKB
t1
B – “hyper-rectangle”
t2
r1
Speaking Requirement Talk
r2
13
QueryDecrypt(PK, DK, C)
• Output
– msg
–
Speaking Requirement Talk
if
if
xB
xB
14
Roadmap
• Trivial construction
• AIBE – MRQED1
– Efficient representation for ranges
– 1 dimensional scheme
• Extension to multiple dimensions
Speaking Requirement Talk
15
Trivial Construction
• 1 dimension
One public key pair for each possible range
- O(T2) public key pairs [ s, t ] [1, T ]
- O(T2) cipher texts and decryption keys for each
range
Performance of D dimensions
Scheme
PK. size
Enc. Cost
CT. Size
DK. Size
Dec. Cost
Trivial
O(T2D)
O(T2D)
O(T2D)
O(D)
O(D)
T: # different values along each dimension
D: # dimensions
Speaking Requirement Talk
16
Roadmap
• Trivial construction
• AIBE – MRQED1
– Efficient representation for ranges
– 1 dimensional scheme
• Extension to multiple dimensions
Speaking Requirement Talk
17
AIBE – MRQED1
• Try to decrease storage and
computation cost
• Efficient representation of range:
- Define Interval Tree tr(T) as a binary tree
over [1, T], each node represents a range
- ith leaf node: cv(ID) = i
- non-leaf node: cv(ID) = cv(ID1) U cv(ID2)
in which ID1 & ID2 are its children nodes
Speaking Requirement Talk
18
AIBE – MRQED1– cont’d
• Set of IDs covering a point x
- if x [1, T ] , ID covers x if x cv( ID).
- Define P(x) to be the set such IDs.
- P(x) includes all nodes on the path
from leaf x to root.
• Range as a collection of IDs
- Define (s, t) to be the minimum set of
nodes that cover range [s, t].
Speaking Requirement Talk
19
AIBE – MRQED1– cont’d
[0, 7]
[0, 3]
[0, 1]
0
1
[4, 7]
[2, 3]
2
3
[4, 5]
4
5
[6, 7]
6
7
[1, 7]
Speaking Requirement Talk
20
AIBE – MRQED1: Encrypt
C0=Encrypt(PK, IDA, msg)
A
C1=Encrypt(PK, IDB, msg)
B
C2
C3
0
Speaking Requirement Talk
1
2
3
4
5
6
7
21
AIBE – MRQED1: Encrypt
C0
O(logT) ciphertext size
C1
C2
C3
0
Speaking Requirement Talk
1
2
3
4
5
6
7
22
AIBE – MRQED1: DeriveKey
0
1
2
3
4
5
6
7
[2, 6]
Speaking Requirement Talk
23
AIBE – MRQED1: DeriveKey
[2, 3]
[4, 5]
[6, 6]
0
1
2
3
4
5
6
7
[2, 6]
Speaking Requirement Talk
24
AIBE – MRQED1: DeriveKey
SK
SK
SK
0
1
2
3
4
5
6
7
[2, 6]
Speaking Requirement Talk
25
AIBE – MRQED1: DeriveKey
O(logT) decryption key size
SK
SK
SK
0
1
2
3
4
5
6
7
[2, 6]
Speaking Requirement Talk
26
AIBE – MRQED1: QueryDecrypt
Observations:
• If x 2 [s, t], then | P(x) Å (s, t) | = 1
• If x 2 [s, t], P(x) Å (s, t) = ;
Speaking Requirement Talk
27
AIBE – MRQED1: Decrypt
C0
C1
C2
C3
0
Speaking Requirement Talk
1
2
3
4
5
6
7
28
AIBE – MRQED1: Decrypt
C0
C1
C2
SK
SK
SK
C3
0
1
2
3
4
5
6
7
[2, 6]
Speaking Requirement Talk
29
AIBE – MRQED1: Decrypt
C0
C1
C2
C3
0
Speaking Requirement Talk
1
2
3
4
5
6
7
30
AIBE – MRQED1: Decrypt
C0
C1
SKB
C2
C3
0
1
2
3
4
5
6
7
[0, 3]
Speaking Requirement Talk
31
AIBE – MRQED1: Decrypt
C0
C1
SKB
C2
C3
0
1
2
3
4
5
6
7
[4, 7]
Speaking Requirement Talk
32
AIBE – MRQED1: Performance
Scheme
PK. size
Enc. Cost
CT. Size
DK. Size
Dec. Cost
Trivial
O(T2D)
O(T2D)
O(T2D)
O(D)
O(D)
AIBE-MRQED1
O(1)
O(logT)
O(logT)
O(logT)
O(logT)
T: # different values along each dimension
D: # dimensions
Speaking Requirement Talk
33
AIBE – MRQEDD – Encryption
D = 2 dimensional
example
To encrypt point
x = (3,5)
Speaking Requirement Talk
34
AIBE – MRQEDD – DeriveKey
Query range:
[2,6] x [7,3]
1st dimension: (2, 6)
2nd dimension: (3,7)
Speaking Requirement Talk
35
AIBE – MRQEDD Performance
• O(1) PK size
• O(D¢logT)
– Encryption cost
– Cipher Text. size
– Decryption key size
• O((logT)D) decrypt. cost
• Good performance, but has a serious
vulnerability – prone to collusion attack
Speaking Requirement Talk
36
Collusion Attack
SKy2 R3
SKy1
R1
Kx1
{SKx1, SKy2}
{SKx1, SKy1}
R4
R2
{SKx2, SKy2}
{SKx2, SKy1}
Kx2
How fix the problem
but preserve the AIBE – MRQEDD efficiency?
Speaking Requirement Talk
37
Collusion Attack solution - “Binding”
x ¢y = c
{SKx2, SKy2}
SKy2
SKy1 {SKx1, SKy1}
SKx1
Speaking Requirement Talk
SKx2
38
Collusion Attack solution - “Binding”
x ¢y = c
{SKx2, SKy2}
SKy2
x 4 SKx1
SKy1 {SKx1, SKy1}
SKx1
Speaking Requirement Talk
SKx2
39
Collusion Attack solution - “Binding”
x ¢y = c
{SKx2, SKy2}
SKy2
xSKx1
SKy1 {SKx1, SKy1}
SKx1
Speaking Requirement Talk
SKx2
40
Collusion Attack solution - “Binding”
x ¢y = c
{SKx2, SKy2}
SKy2
xSKx1
ySKy1
SKy1 {SKx1, SKy1}
SKx1
Speaking Requirement Talk
SKx2
41
Collusion Attack solution - “Binding”
SKy2x ¢ y = c
{SKx2, SKy2}
xSKx2
SKy1
{SKx1, SKy1}
SK
y
y2
SKx1
Speaking Requirement Talk
SKx2
42
The “Binding” Construction
• Use Bilinear Groups
• Rely on well-known difficult problem:
– Decision BDH Assumption
– Decision linear Assumption
• Algebraically intensive
Speaking Requirement Talk
43
Conclusion
Scheme
PK. size
Enc. Cost
CT. Size
DK. Size
Dec. Cost
Trivial
O(T2D)
O(T2D)
O(T2D)
O(D)
O(D)
BW06
O(D¢T)
O(D¢T)
O(D¢T)
O(D)
O(D)
RQEQD
O(D∙logT)
O(D∙logT)
O(D∙logT)
O(D∙logT) O((logT)D)
T: # different values along each dimension
D: # dimensions
Speaking Requirement Talk
44
Future work
• Further exploration of ways to decrease
the decryption co
• Possible other privacy-preserving
applications in addition to network audit
logs, financial audit logs, etc.
Speaking Requirement Talk
45
Question
Observations:
• If x 2 [s, t], then | P(x) Å (s, t) | = 1
• If x 2 [s, t], P(x) Å (s, t) = ;
Why is this always true?
Speaking Requirement Talk
46
Thank you!