Dynamic Searchable Symmetric Encryption (DSSE) reconciles data confidentiality and usability in outsourced storage systems by enabling keyword search and continuous data update over encrypted data. Conjunctive DSSE, as an expressive variant of DSSE, allows clients to retrieve data matching multiple keywords simultaneously. All existing conjunctive DSSE schemes, as we know, assume that the secret-key remains perfectly secure; however, key compromise incidents occur frequently in practice. Once the secret-key is compromised, existing conjunctive DSSE schemes lose their privacy guarantees entirely. To address this issue, we define a new framework for conjunctive DSSE with key update and introduce post-compromise security under the paradigm of leakage function. Within this framework, we develop ${\sf Poseidon}$, the first conjunctive DSSE scheme that achieves post-compromise security. We provide a formal security proof showing that ${\sf Poseidon}$ preserves both data confidentiality and operation privacy even if the secret-key is leaked to the adversary. We conduct an extensive performance assessment of ${\sf Poseidon}$ on real-world datasets and benchmark it against current conjunctive DSSE schemes under the same security level. The results show that ${\sf Poseidon}$ achieves 1.58$\sim 4.99\times$ speedup in search time beyond the prior and fastest scheme and incurs comparable communication overhead and update latency.
Oblivious RAM (ORAM) is a fundamental cryptographic primitive that enables secure access to encrypted data while hiding access patterns. It has been widely adopted in privacy-preserving storage and secure computation applications. Among various ORAM constructions, tree-based ORAM schemes have gained prominence due to their practical efficiency. However, most existing tree-based ORAM designs are static, making them unsuitable for applications requiring frequent data updates. In this work, we address this limitation by introducing a generic transformation framework that enables dynamic expansion and contraction of tree-based ORAMs. Our approach integrates a reverse lexicographic order scheduling for terminal node insertion and pruning, along with a deepest virtual level mapping mechanism to efficiently manage the position map. This design ensures scalability while avoiding frequent update of the position map. We implement our framework for state-of-the-art Path ORAM, Circuit ORAM, and Ring ORAM, and conduct extensive evaluations. The results demonstrate that compared to their original static counterparts and the scheme of Moataz et al., our schemes significantly reduce bandwidth overhead by up to 7×, making tree-based ORAMs more practical for real-world applications, such as oblivious priority queue and dynamic searchable encryption.
A commitment protocol enables a sender to fix a message without revealing or altering it until later, which is crucial for various cryptographic protocols and applications. However, traditional commitments risk coercion, where an entity, named dictator, can force premature opening or involuntary commitments. This coercive entity was initially explored in encryption by Persiano et al. at EUROCRYPT’22. This work investigates how to circumvent the dictator in commitment, considering the dictator’s enhanced ability to influence the sender by tampering with public parameters. We note that from inception to today, commitments were defined and employed under a passive adversary, and this work, therefore, conceptually demonstrates how the “anamorphic perspective” can enrich the relevant adversarial settings of basic primitives. Specifically, we formalize dictator’s capabilities for undermining commitments-ranging from weak to strong models-and establish reductions among them. To counter coercion, we propose “anamorphic commitment”, a novel primitive that allows the sender to embed a covert message within an innocent-looking commitment to alert to coercion or transmit secret information. We define the syntax, security models, and robustness of anamorphic commitment, and present two generic constructions with distinct performance advantages that can integrate seamlessly with the standard commitments.
Dynamic Searchable Symmetric Encryption (DSSE) allows clients to update data and search keywords securely over symmetrically encrypted data on an honest but curious server. Conjunctive DSSE, an attractive type of DSSE with expressive search, enables clients to find data containing multiple keywords simultaneously. However, recently proposed efficient conjunctive DSSE schemes, such as ODXT (in NDSS’21) and SDSSE-CQ (in PETS’25), all rely on cross-tag techniques and suffer from either forward privacy or volume-privacy leakages arising from conjunctive keywords, making them vulnerable to injection or leakage-abuse attacks. In this work, we analyze the aforementioned works in depth and design a new conjunctive DSSE scheme named FDXT. For any search query with multiple keywords, FDXT guarantees the forward privacy of all queried keywords. In contrast, ODXT only maintains the forward privacy of the single and first queried keyword. FDXT also avoids volume leakage compared with SDSSE-CQ. Finally, we compared FDXT with ODXT and SDSSE-CQ in terms of performance on the Crime, Wikipedia, and Enron datasets. The experimental results show that FDXT exhibits good performance, which is comparable to ODXT and significantly better than SDSSE-CQ.
The Internet of Vehicles (IoV) is widely applied in intelligent transportation systems, enhancing driving safety and service quality. Currently, most research on identity authentication in IoV focuses on initial authentication, while only a few studies consider the handover authentication process, which is of high dynamics, resource constraints, and low efficiency, whereas crucial in the mobile edge computing (MEC) scenario of IoV. Consequently, an authentication and key agreement scheme is proposed. A distributed registration architecture with dynamic load awareness is constructed, enabling optimal resource allocation and reducing authentication delay through coordinated operations between the master and subregistration centers, in which ensuring low overhead for vehicle terminals and enhancing users' privacy and security are provided by offloading complex computational tasks to edge nodes (ENs). Furthermore, a trajectory prediction-driven pre-handover authentication mechanism is introduced, which significantly improves handover efficiency. Additionally, a fast reauthentication protocol is designed to effectively alleviate the burden of repeated registration caused by short-term vehicle disconnections. The semantic security of session keys is proven under the real-or-random model. The confidentiality and authenticity of the proposed scheme are formally verified using the ProVerif tool. Security and performance analyses demonstrate that the scheme satisfies security properties, including forward secrecy, unlinkability, and identity traceability. Furthermore, the proposed scheme exhibits superior efficiency relative to comparable schemes.
Public-key encryption with keyword search (PEKS) is a powerful cryptographic primitive that enables a receiver to search keywords over ciphertexts hosted on an honest-but-curious server in the asymmetric-key setting while hiding the keywords from the server. Many researchers have devoted their efforts to achieving expressive search, security against keyword guessing attacks, and efficient search performance. However, until now, no effective PEKS scheme can achieve verifiable search completeness in the standard PEKS security model. In practice, the server may intentionally or unintentionally lose the receivers’ data. Hence, verifiable search completeness is essential for receivers to audit the service quality of the server. To address this problem, this work develops a blockchain-based PEKS framework. This framework only utilizes the distributed ledger role of the blockchain, making it general. Additionally, we find that existing PEKS schemes cannot be efficiently deployed into the framework due to the inefficient use of randomness, which increases the ciphertext sizes. To tackle this problem, we utilize randomness reuse technique to propose a novel PEKS scheme. The proposed scheme achieves linear search complexity with respect to the total number of files in the dataset. To demonstrate the efficiency of our scheme, we perform comprehensive experiments to evaluate it and three other state-of-the-art schemes. The experimental results show that our PEKS scheme is superior to existing PEKS schemes in both the encryption and search phases and significantly reduces the sizes of generated ciphertexts.
Dynamic Searchable Symmetric Encryption (DSSE) allows secure searches over a dynamic encrypted database but suffers from inherent information leakage. Existing passive attacks against DSSE rely on persistent leakage monitoring to infer leakage patterns, whereas this work targets intermittent observation - a more practical threat model. We propose Peekaboo - a new universal attack framework and the core design relies on inferring the search pattern and further combining it with auxiliary knowledge and other leakage. We instantiate Peekaboo over the SOTA attacks, Sap ( USENIX' 21) and Jigsaw (USENIX' 24), to derive their "+" variants (Sap+ and Jigsaw+). Extensive experiments demonstrate that our design achieves >0.9 adjusted rand index for search pattern recovery and similar to 90% query accuracy vs. FMA's similar to 30% (CCS' 23). Peekaboo's accuracy scales with observation rounds and the number of observed queries but also it resists SOTA countermeasures, with >40% accuracy against file size padding and >80% against obfuscation.
Oblivious RAM (ORAM) allows a client to securely retrieve elements from outsourced servers without leakage about the accessed elements or their virtual addresses. Two-server ORAM, designed for secure two-party RAM computation, stores data across two non-colluding servers. However, many two-server ORAM schemes suffer from excessive local storage or high bandwidth costs. To serve lightweight clients, it is crucial for ORAM to achieve concretely efficient bandwidth while maintaining O(1) local storage. Hence, this paper presents two new client-friendly two-server ORAM schemes that achieve practical logarithmic bandwidth under O(1) local storage, while incurring linear symmetric key computations. The core design features a hierarchical structure and a pairwise-area setting for the elements and their tags. Accordingly, we specify efficient read-only and write-only private information retrieval (PIR) algorithms in our schemes to ensure obliviousness in accessing two areas respectively, so as to avoid the necessity of costly shuffle techniques in previous works. We empirically evaluate our schemes against LO13 (TCC'13), AFN17 (PKC'17), and KM19 (PKC'19) in terms of both bandwidth and time cost. The results demonstrate that our schemes reduce bandwidth by approximately 2-4x compared to LO13, and by 16-64x compared to AFN17 and KM19. For a database of size 2^14 blocks, our schemes are over 64x faster than KM19, while achieving similar performance to LO13 and AFN17 in the WAN setting, with a latency of around 1 second.
The burgeoning complexity of communication necessitates a high demand for security. Access control encryption is a promising primitive to meet the security demand but the bulk of its constructions rely on formulating the access control policy with identities. Attribute-based access control policy in attribute-based encryption (ABE) is known to be more expressive without relying on enumerating identities. We propose a generic framework to build attribute-based access control encryption from ciphertext-policy ABE. Our instantiations prioritize different emphases on expressiveness and efficiency. The first instantiation supports multi-valued AND-gate access control structures, while the second supports the linear-secret-sharing access structure. Both are prototyped with efficiency validated empirically.
Public-key encryption with keyword search (PEKS) is a well-known method for privacy-preserving keyword search in encrypted email systems due to its public-key characteristics. However, we have observed that even without a keyword-search trapdoor, traditional PEKS allows the server to distinguish ciphertexts effectively, compromising semantic security. To address this limitation, we introduce dynamic searchable public-key encryption (DSPE), a concept that conceals relationships between searchable ciphertexts and their corresponding encrypted files, ensuring semantic security in both theory and practice. DSPE also enables the server to delete specific ciphertexts as requested by the receiver. We present a DSPE instance with provable semantic security in the random oracle model, which offers the advantage of sublinear complexity in identifying matching ciphertexts and deleting intended ones. Through experimental validation, we demonstrate the feasibility of this instance. Furthermore, we construct a DSPE-based cloud email system in the double-cloud model and evaluate its performance.
Fully Homomorphic Encryption (FHE) allows computations to be performed on encrypted data, providing a promising solution for privacy-preserving computing. As a pivotal advancement in FHE, CKKS is ideally suited for privacy-preserving Convolutional Neural Network (CNN) inference, leveraging its capability for real-number arithmetic and Single-Instruction-Multiple-Data (SIMD) advantages. However, the inherent computational and storage complexities of CKKS pose substantial challenges in terms of latency and resource consumption. In this paper, we propose an FPGA-based framework to accelerate CKKS-based privacy-preserving CNN inference. It supports full-slot packing for homomorphic convolution across all ResNet20 layers, minimizing the overall overhead of homomorphic evaluation. Concurrently, through optimized data flow scheduling and pipeline design, this framework delivers high-throughput performance for CNN inference of encrypted images, which is more efficient than the state-of-the-art solution on FPGA.
The honey password vault is a promising method for managing user passwords and mitigating password-guessing attacks by creating plausible-looking decoy password vaults. Recently, various methods, such as Chatterjee-PCFG (IEEE S&P'15), Golla-Markov (ACM CCS'16), and Cheng-IUV (USENIX Security'21), have been proposed to construct the cornerstone of honey password vaults, known as the distribution transforming encoder (DTE). These innovations significantly enhance the security and functionality of each kind of DTE. However, our findings indicate that when users employ multiple honey password vaults of distinct DTEs to manage their passwords, a passive attacker can easily compromise user passwords by exploiting differences among those DTEs. Consequently, we propose the differential attack targeting existing honey password vaults. The extensive experimental results confirm the effectiveness of this attack, distinguishing real from decoy password vaults with accuracy from 99.13% to 100.00%. In response, we design a novel, collaborative approach to train DTE, called federated DTE model, and construct a secure honey password vault. This strategy markedly bolsters security, reducing the differential attack's distinguishing accuracy to approximately 52.41%, nearing the ideal threshold of 50.00%. Our findings emphasize the need for collaborative strategies to maintain password security to combat advanced cyber threats.
Fully Homomorphic Encryption (FHE) enables computation over encrypted data, but it faces significant challenges in practical implementation due to its high computational costs, particularly in HMult, HRot, and Bootstrapping operations. This work presents Athena, an accelerated FHE system built on GPUs with a new algorithm-hardware co-design approach. Specifically, to accelerate HMult, HRot, and Bootstrapping, we redesign their common and expensive operation KeySwitch, based on the KLSS method proposed by Kim et al. in CRYPTO’23, and accelerate its core operations, namely NTT, EBConv, and IP. We further optimize the dataflow of Bootstrapping by reducing redundant EBConv and (I)NTT operations, and by improving the global memory I/O in the double-hoisting-based C2S/S2C operation. Moreover, Athena is designed as a general-purpose system that supports various cryptographic parameters. Experimental results demonstrate that Athena significantly improves the performance of KeySwitch and Bootstrapping. In particular, Athena’s accelerated KeySwitch optimizes HMult 2.17×∼ 4.40× and HRot 1.89×∼ 4.54× compared to TensorFHE (HPCA’23), Poseidon (HPCA’23), and FAB (HPCA’23), respectively. Besides, Athena’s Bootstrapping outperforms TensorFHE by nearly 2.74× .
Public key Encryption with Keyword Search (PEKS) has emerged as a solution for the receiver to securely search the sender’s encrypted data on the cloud. However, the PEKS scheme is threatened by the Keyword Guessing Attack (KGA), which leaks the receiver’s keyword privacy. To resist KGA, researchers have inherited the authentication mechanism into the PEKS system (PAEKS) but also forbid using one trapdoor to search all sender’s encrypted data. In this paper, we explore the KGA problem from grouping senders and propose the notion of Identity-based Group Encryption with Keyword Search (IBGEKS), which leverages Identity-based cryptography to securely search encrypted data. Compared with the PAEKS scheme, the IBGEKS scheme can search the sender’s ciphertexts within the same group established by the receiver via one receiver’s trapdoor. For security, we analyze the KGA problem and propose ciphertexts, identities, and trapdoors indistinguishability for IBGEKS. The evaluation depicts that the IBGEKS has competitive algorithm performance with other SA-PEKS and PAEKS schemes and has superior search performance on the Enron email dataset.
Searchable symmetric encryption schemes often unintentionally disclose certain sensitive information, such as access, volume, and search patterns. Attackers can exploit such leakages and other available knowledge related to the user's database to recover queries. We find that the effectiveness of query recovery attacks depends on the volume/frequency distribution of keywords. Queries containing keywords with high volumes/frequencies are more susceptible to recovery, even when countermeasures are implemented. Attackers can also effectively leverage these “special” queries to recover all others. By exploiting the above finding, we propose a Jigsaw attack that begins by accurately identifying and recovering those distinctive queries. Leveraging the volume, frequency, and co-occurrence information, our attack achieves 90% accuracy in three tested datasets, which is comparable to previous attacks (Oya et al., USENIX' 22 and Damie et al., USENIX' 21). With the same runtime, our attack demonstrates an advantage over the attack proposed by Oya et al (approximately 15% more accuracy when the keyword universe size is 15k). Furthermore, our proposed attack outperforms existing attacks against widely studied countermeasures, achieving roughly 60% and 85% accuracy against the padding and the obfuscation, respectively. In this context, with a large keyword universe (≥3k), it surpasses current state-of-the-art attacks by more than 20%.
Recently, the realm of deep learning applied to 3D point clouds has witnessed significant progress, accompanied by a growing concern about the emerging security threats to point cloud models. While adversarial attacks and backdoor attacks have gained continuous attention, the potentially more detrimental availability poisoning attack (APA) remains unexplored in this domain. In response, we propose the first APA approach in 3D point cloud domain (PointAPA), which utilizes class-wise rotations to serve as shortcuts for poisoning, thus satisfying efficiency, effectiveness, concealment, and the black-box setting. Drawing inspiration from the prevalence of shortcuts in deep neural networks, we exploit the impact of rotation in 3D data augmentation on feature extraction in point cloud networks. This rotation serves as a shortcut, allowing us to apply varying degrees of rotation to training samples from different categories, creating effective shortcuts that contaminate the training process. The natural and efficient rotating operation makes our attack highly inconspicuous and easy to launch. Furthermore, our poisoning scheme is more concealed due to keeping the labels clean (i.e., clean-label APA). Extensive experiments on benchmark datasets of 3D point clouds (including real-world datasets for autonomous driving) have provided compelling evidence that our approach largely compromises 3D point cloud models, resulting in a reduction in model accuracy ranging from 40.6 https://github.com/wxldragon/PointAPA .
Dynamic Searchable Encryption (DSE) has emerged as a solution to efficiently handle and protect large-scale data storage in encrypted databases (EDBs). Volume leakage poses a significant threat, as it enables adversaries to reconstruct search queries and potentially compromise the security and privacy of data. Padding strategies are common countermeasures for the leakage, but they significantly increase storage and communication costs. In this work, we develop a new perspective to handle volume leakage. We start with distinct search and further explore a new concept called \textit{distinct} DSE (\textit{d}-DSE). We also define new security notions, in particular Distinct with Volume-Hiding security, as well as forward and backward privacy, for the new concept. Based on \textit{d}-DSE, we construct the \textit{d}-DSE designed EDB with related constructions for distinct keyword (d-KW-\textit{d}DSE), keyword (KW-\textit{d}DSE), and join queries (JOIN-\textit{d}DSE) and update queries in encrypted databases. We instantiate a concrete scheme \textsf{BF-SRE}, employing Symmetric Revocable Encryption. We conduct extensive experiments on real-world datasets, such as Crime, Wikipedia, and Enron, for performance evaluation. The results demonstrate that our scheme is practical in data search and with comparable computational performance to the SOTA DSE scheme (\textsf{MITRA}*, \textsf{AURA}) and padding strategies (\textsf{SEAL}, \textsf{ShieldDB}). Furthermore, our proposal sharply reduces the communication cost as compared to padding strategies, with roughly 6.36 to 53.14x advantage for search queries.
Dynamic Searchable Symmetric Encryption (DSSE) is a prospective technique in the field of cloud storage for secure search over encrypted data. A DSSE client can issue update queries to an honest-but-curious server for adding or deleting his ciphertexts to or from the server and delegate keyword search over those ciphertexts to the server. Numerous investigations focus on achieving strong security, like forward-and-Type-I--backward security, to reduce the information leakage of DSSE to the server as much as possible. However, the existing DSSE with such strong security cannot keep search correctness and stable security (or robustness, in short) if irrational queries are issued by the client, like duplicate add or delete queries and the delete queries for removing non-existed entries, to the server unintentionally. Hence, this work proposes two new DSSE schemes, named SR-DSSEa and SR-DSSEb , respectively. Both two schemes achieve forward-and-Type-I--backward security while keeping robustness when irrational queries are issued. In terms of performance, SR-DSSEa has more efficient communication costs and roundtrips than SR-DSSEb . In contrast, SR-DSSEb has a more efficient search performance than SR-DSSEa . Its search performance is close to the existing DSSE scheme with the same security but fails to achieve robustness.
It is natural for Internet users to use a password vault to encrypt and manage numerous passwords with a master password. Using one to rule all that is handy but attackers can focus on breaking the vault by brute-force attacking the master password. The honey password vault is proposed to handle the above security concern. It traps the attacker by generating a plausible decoy vault when decrypting the password vault with a “guessing” master password, such that it is hard for the attacker to obtain the real vault. Following the seminal work (S P’15), many schemes have been proposed to counter advanced attacks, e.g., the Kullback-Leibler divergence attack (CCS’16), encoding attack (USENIX Security’19), and intersection attack (USENIX Security’21). But we find that they barely capture the security after the master password is reset. Once the reset is completed, the attacker can identify the decoy vault by decrypting and comparing the old and new versions of a password vault. To prove this, we propose a new master password guessing attack (MPGA) to break all the existing honey password vault schemes. Experimental results show that MPGA can easily distinguish real and decoy vaults with 99.12
Cryptographic Hardware Engineering (CHE) is an emerging field that amalgamates cryptography principles with hardware design and implementation. It plays an increasingly important role as secure and trustworthy computing and communication is needed in all applications. In order to introduce CHE into undergraduate curriculum to prepare the next generation workforce, students must have a solid theoretical foundation in cryptography, be proficient in digital circuit design, and have access to commercial design tools and equipment. In this paper, we report our experience in developing and teaching a CHE course for junior students. The course consists of three components that are complementary to each other: digital circuits and FPGA design fundamentals, hardware implementation of cryptographic algorithms, and security analysis of cryptographic hardware. Through this course, students get a good comprehension of CHE principles and gain hands-on experience in secure cryptographic hardware design and analysis.