ISSN 1000-1239 CN 11-1777/TP

Journal of Computer Research and Development ›› 2021, Vol. 58 ›› Issue (10): 2287-2300.doi: 10.7544/issn1000-1239.2021.20210614

Special Issue: 2021密码学与网络空间安全治理专题

Previous Articles     Next Articles

A Multi-Pattern Hiding Dynamic Symmetric Searchable Encryption Based on Differential Privacy

Zhao Ziting1, Xu Yin1, Song Xiangfu2, Jiang Han1,3   

  1. 1(School of Software, Shandong University, Jinan 250101);2(School of Computer Science and Technology, Shandong University, Jinan 250101);3(Key Laboratory of Software Engineering of Shandong Province (Shandong University), Jinan 250101)
  • Online:2021-10-01
  • Supported by: 
    This work was supported by the National Natural Science Foundation of China (61632020) and the Special Project of Science and Technology Innovation Base of Key Laboratory of Software Engineering of Shandong Province (11480004042015).

Abstract: Dynamic Symmetric Searchable Encryption (DSSE) has become one of the most important primitives for data privacy protection in recent years. It allows clients to efficiently retrieve and update encrypted data stored in cloud servers. Only a small amount of strictly defined leakage is disclosed to the server, such as search pattern, access pattern, update pattern, and volume pattern. However, a growing number of studies have found that some powerful adversaries can exploit DSSE leakage to carry out specific attacks that undermine the privacy of data and retrieval. In the past, Private Information Retrieval, Oblivious Random Access Machine and storage padding are often used to compress or even eliminate the leaked information. These technologies can provide better security, but they are difficult to be applied because of the high complexity of computation, communication and storage. In order to achieve a better balance between safety and efficiency, this paper proposes the following ideas: We first introduce a meaningful security concept-differential privacy and propose a new padding method, differential privacy padding(DPP), which can reduce the storage load while ensuring the security. Then a Dynamic search update scheme called “MDSSE” is proposed in the multi-server mode. Through DPP apply to our scheme, volume, update and search pattern hiding are realized. The forward privacy and back privacy security are guaranteed at the same time. For the security proof of the scheme, we extend the definition of update history and propose a differential Update history DP-Update which is suitable for this scheme. Experimental results show that our scheme can resist leakage and abuse attacks, it also provides high storage and communication efficiency.

Key words: dynamic symmetric searchable encryption (DSSE), differential privacy, multi-server setting, forward privacy, leakage-hiding

CLC Number: