论文标题

加强与差分隐私保护加密的订单

Strengthening Order Preserving Encryption with Differential Privacy

论文作者

Chowdhury, Amrita Roy, Ding, Bolin, Jha, Somesh, Liu, Weiran, Zhou, Jingren

论文摘要

订单保存加密(OPE)方案的密文保留其相应的明文的顺序。但是,OPES容易受到利用该保留顺序的推理攻击。另一方面,差异隐私已成为获得数据隐私的事实标准。 DP最有吸引力的属性之一是,对DP算法的嘈杂输出执行的任何后处理(推论)计算都不会降低其隐私保证。在本文中,我们提出了一种新颖的私人订单保存加密方案,即$ε$。在Op $ε$下,从密文中的订单泄漏是私人的。结果,至少,即使面对推理攻击,op $ε$也可以确保正式保证(特别是放松的DP保证)。据我们所知,这是将DP与保留物业加密方案相结合的第一项工作。我们通过在四个现实世界数据集上进行了广泛的经验评估来证明Op $ε$的实用性在回答范围查询方面。例如,OP $ε$仅在每$ 10K $中仅$ 4 $ $ 4 $正确的记录,对于$ \ sim732k $的数据集,具有域尺寸$ \ sim18k $和$ε= 1 $的属性。

Ciphertexts of an order-preserving encryption (OPE) scheme preserve the order of their corresponding plaintexts. However, OPEs are vulnerable to inference attacks that exploit this preserved order. At another end, differential privacy has become the de-facto standard for achieving data privacy. One of the most attractive properties of DP is that any post-processing (inferential) computation performed on the noisy output of a DP algorithm does not degrade its privacy guarantee. In this paper, we propose a novel differentially private order preserving encryption scheme, OP$ε$. Under OP$ε$, the leakage of order from the ciphertexts is differentially private. As a result, in the least, OP$ε$ ensures a formal guarantee (specifically, a relaxed DP guarantee) even in the face of inference attacks. To the best of our knowledge, this is the first work to combine DP with a property-preserving encryption scheme. We demonstrate OP$ε$'s practical utility in answering range queries via extensive empirical evaluation on four real-world datasets. For instance, OP$ε$ misses only around $4$ in every $10K$ correct records on average for a dataset of size $\sim732K$ with an attribute of domain size $\sim18K$ and $ε= 1$.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源