A SaaS-Native Wildcard Searchable Encryption Scheme for Protecting Privacy in Cloud Services

Shen‐Ming Chung, Ming‐Der Shieh, Tzi‐cker Chiueh · 2019

As GDPR and similar regulations are taking a more important role in business, cloud services lacking privacy-protection mechanisms could suffer the most. Fortunately, some technical solutions do exist and, among them, Searchable Encryption (SE) stands out as the most efficient one to address the privacy issue while allowing services to do the jobs. However, though providing both confidentiality and searchability for the private data stored in semi-trusted environments such as cloud, SE is rarely deployed in cloud services because most SE schemes are either lacking decent query expressiveness or requiring database modifications, and thus is not native to Software-as-a-Service (SaaS) running in clouds. Considering the modification on existing databases would bring instability and even risks to cloud services, in this paper we present a wildcard SE scheme named FETCH that is able to work with off-the-shelves databases without requiring any modification. Our idea is to transform the problem of wildcard SE searching into a problem of subsequence matching. Since the transformed problem can be easily tackled by most databases, our scheme proves to fit well with SaaS in general with high efficiency. However, a caution has to be noticed that, for the outstanding performance, our scheme is actually trading off theoretical indistinguishability. Therefore, in this paper security discussions are also given to elaborate both strength and weakness of the proposed FETCH.

Read the paper · More papers on PaperTik