Encryption provides a method to protect data outsourced to a DBMS provider, e.g., in the cloud. However, performing database operations over encrypted data requires specialized encryption schemes that carefully balance security and performance. In this paper, we present a new encryption scheme that can efficiently perform equi-joins over encrypted data with better security than the state-of-the-art. In particular, our encryption scheme reduces the leakage to equality of rows that match a selection criterion and only reveals the transitive closure of the sum of the leakages of each query in a series of queries. Our encryption scheme is provable secure. We implemented our encryption scheme and evaluated it over a dataset from the TPC-H benchmark.
翻译:加密提供了一种保护数据的方法,将数据外包给DBMS提供商,例如,在云层中。然而,对加密数据进行数据库操作需要专门的加密计划,以谨慎地平衡安全和性能。在本文中,我们提出了一个新的加密计划,能够以比最新技术更安全的方式有效地对加密数据进行假相。特别是,我们的加密计划将渗漏降低到与选择标准相符的行的等同水平,并且只显示在一系列查询中每个查询的渗漏总和的过渡性结束。我们的加密计划是安全的。我们实施了我们的加密计划,并对TPC-H基准的数据集进行了评估。