This report systematically presents attack methodologies, defense mechanisms, security proofs, and experimental evaluations on seven real-world datasets as well as introducing BlindGES, an enhanced scheme incorporating a Merge-and-Divide mechanism and two-level multimap index that reduces one-to-one mappings to below 20%, cuts setup time by 50%, reduces storage overhead by 32%, and limits path length leakage to under 1%.
Abstract
Graph encryption schemes (GES) enable secure outsourcing of graph data while supporting efficient queries. This report provides a comprehensive analysis of structural leakage in GES for single-pair shortest path (SPSP) queries, integrating findings from two recent works. First, we analyze PathGES, a scheme designed to resist query recovery attacks through heavy-light decomposition (HLD) and canonical fragment encoding. Our analysis reveals that PathGES suffers from significant imbalances in HLD decomposition, with over 99% of token-path mappings being one-to-one on real-world datasets, enabling both the Falzon-Paterson attack and side-channel inference of path lengths. Second, we present Fragment Tree attack that exploits these structural weaknesses to recover query contents, achieving up to 10.24% exact recovery on sparse graphs. Third, we introduce BlindGES, an enhanced scheme incorporating a Merge-and-Divide mechanism and two-level multimap index that reduces one-to-one mappings to below 20%, cuts setup time by 50%, reduces storage overhead by 32%, and limits path length leakage to under 1%. This report systematically presents attack methodologies, defense mechanisms, security proofs, and experimental evaluations on seven real-world datasets.
This paper introduces a novel secure lineage verification system based on Directed Acyclic Graphs (DAGs) and homomorphic hash functions, VERDICT, which incorporates bucket indexing and Merkle tree verification to provide cryptographic guarantees of data and event existence.
Bilel Zaghdoudi, M. Potop-Butucaru· IACR Cryptology ePrint Archi...· 0 citations
Dynamic Searchable Symmetric Encryption (DSSE) enables efficient searches over encrypted data but often suffers from search pattern leakage, allowing adversaries to infer sensitive information. While schemes using Oblivious RAM (ORAM) mitigate leakage, their high cost hinders large-scale applications. Dory adopts a mul...
Man-Yue Hu, Cong Zuo, Shu-Jie Cui et al.· IEEE Transactions on Informa...· 0 citations
This paper presents a structured review of privacy-preserving data processing techniques for cloud environments built on HE and FL, individually and in hybrid combination, and identifies promising directions for future research.
Shivendra Shukla, C. S. Gautam, Divyansh Tiwari· International Journal of Cre...· 0 citations
Fine-grained access control (FGAC) mechanisms such as row-level security (RLS) and document-level security (DLS) are widely deployed in databases to restrict access to data stored in physical indexing structures shared by multiple users (e.g., in multi-tenant databases, or in the implementation of least-privilege withi...
As knowledge graphs are increasingly applied in sensitive domains such as healthcare, ensuring data confidentiality and fine-grained access control over outsourced graph data has become critical. In this paper, we propose EFKG, an Efficient and Fine-grained Access Control Encrypted Knowledge Graph construction scheme t...
As a classical type of machine learning algorithms, tree models have been widely employed in various fields, such as financial analysis and health diagnostics, offering high-accuracy and low-latency prediction services to users. However, tree evaluation also raises significant privacy concerns, particularly with respec...
Jia-Qi Zhao, Hui Zhu, Jun-Peng Zhang et al.· IEEE Transactions on Informa...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.