Authors:
Ines Kramer
;
Silvia Schmidt
;
Manuel Koschuch
and
Mathias Tausig
Affiliation:
Competence Centre for IT Security, University of Applied Sciences FH Campus Wien, Vienna, Austria
Keyword(s):
Searchable Encryption, Dynamic Symmetric Searchable Encryption, Implementation, Framework, Forward Privacy.
Abstract:
In this work we present a prototype implementation of a framework for searchable encryption (SE), “Searchitect”. Our framework can be used to extend applications with search functionality over encrypted data in a protocol agnostic approach, hopefully paving the way for a broader and easier adoption of this promising privacy enhancing technology. Furthermore, it allows for easy comparison and evaluation of different implementations of SE schemes. We discuss dynamic searchable encryption schemes, supporting efficient updates of an encrypted index, as well as forward secure schemes that guarantee additional security properties, which resist file injection attacks. We evaluate the performance characteristics of two implementations of existing forward secure schemes, DynRH and Sophos. Our results show that the DynRH implementation is outperforming Sophos in terms of efficiency in the execution time of the search and update protocol, but needs more bandwidth for a search request. In additi
on, we augment an existing cloud-storage application with SE functionality using our framework, showing the negligible additional effort required by the implementers to accomplish this.
(More)