RUS  ENG
Full version
JOURNALS // Prikladnaya Diskretnaya Matematika. Supplement // Archive

Prikl. Diskr. Mat. Suppl., 2014 Issue 7, Pages 81–82 (Mi pdma147)

Mathematical Foundations of Computer Security

Computationally secure DBMS based on order-preserving encryption

I. Glotov, S. Ovsyannikov, V. Trenkaev

Tomsk State University, Tomsk

Abstract: The paper presents a computationally secure database management system based on order-preserving encryption. The threat model is the following: the DB server is leased to the client thus the DB server is untrusted; the threat is a malicious database administrator who tries to learn private data by snooping on the DB server. To protect data confidentiality against this threat, it is proposed to execute queries over encrypted data on the untrusted server. Namely, to perform order operations on ciphertexts in the same way as on plaintexts, an order-preserving encryption, in particular mOPE scheme, is used. The mOPE scheme achieves IND-OCPA security, where an adversary learns no information about the plaintexts besides order. A MySQL plugin that implements a NoSQL protocol for MySQL server is developed. The NoSQL client/server protocol supports simple operations on private data, in particular it ranges queries over encrypted data. The protocol allows client applications to communicate remotely with MySQL storage engines.

Keywords: secure DBMS, untrusted DB server, order-preserving encryption, NoSQL protocol.

UDC: 004.65+004.056.55



© Steklov Math. Inst. of RAS, 2024