Stateful Order-Preserving Encryption With Dummy Ciphertexts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing order-preserving encryption techniques lack sufficient security as they maintain plaintext order information in ciphertexts, making it easy for attackers to infer plaintext sets from statistical characteristics, and they cannot be directly applied to databases without compromising query operations.
Innovation Solution
A method involving generating dummy ciphertexts and adding them to a ciphertext set, along with order-preserving ciphertexts, and using state information variables to manage and filter candidate ciphertexts based on search conditions, ensuring attackers cannot distinguish between actual and dummy ciphertexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If order-preserving encryption is applied to enable efficient search queries on encrypted data, then search efficiency is improved, but security deteriorates because attackers can infer plaintext sets from statistical characteristics of ciphertexts
Solution Approach 1:
The patent creates dummy ciphertexts that are copies or simulations of real ciphertexts, indistinguishable from actual encrypted data. These dummy ciphertexts are generated to match the statistical characteristics of real ciphertexts, allowing the system to maintain search efficiency while preventing attackers from inferring plaintext sets, thus resolving the security vulnerability of traditional order-preserving encryption
Solution Approach 2:
The patent modifies the parameter space by introducing state information variables and organizing ciphertexts into multiple subsets with different state values. This parameter change allows the system to preserve order information for search operations while adding an additional layer of complexity that prevents statistical analysis attacks, thereby improving security without sacrificing search efficiency
2Reliability
If dummy ciphertexts are generated and added to the ciphertext set to prevent plaintext inference, then security is improved, but device complexity increases due to multiple ciphertext subsets and state information management
Solution Approach 1:
The patent divides the ciphertext set into multiple subsets, each associated with a specific state information variable value. This segmentation allows the system to manage complexity by organizing dummy and real ciphertexts into discrete, manageable groups while maintaining the overall security goal of preventing plaintext inference through the combined structure
3Reliability
If multiple ciphertext subsets with state information variables are used to enhance security, then security against statistical analysis is improved, but ease of operation deteriorates due to the need to manage and filter ciphertexts based on state information
Solution Approach 1:
The state information variable serves multiple functions simultaneously: it organizes ciphertexts into subsets for security purposes, enables efficient filtering during search operations, and provides a mechanism for tracking and managing dummy versus real ciphertexts. This multi-functionality reduces the operational burden despite the increased structural complexity
Data Source
AI summary
Disclosed herein is a method and apparatus for stateful order-preserving encryption for enhancing security. The method includes generating an order-preserving ciphertext by performing order-preserving encryption on a plaintext, generating a plurality of dummy ciphertexts corresponding to a preset variable for the order-preserving ciphertext, and adding the order-preserving ciphertext and the plurality of dummy ciphertexts to a ciphertext set.


