Abstract
Encrypted databases (EDBs) have become the de facto technique to ensure data confidentiality in database outsourcing scenarios. Among them, HEDB is a state-of-the-art EDB system that balances full-SQL functionality, efficient maintainability, and rigorous security. However, we identify a critical vulnerability in its maintenance mode and design the first attack of its kind against EDB systems. Specifically, we introduce substitution and replay attacks (SARAs) launched by database administrators (DBAs) against the HEDB system. Subsequently, we craft an automatic attack tool, Auto SARAs, to demonstrate the real-life impact of this attack. The experimental results on the TPC-H benchmark show that SARAs can successfully compromise 1,449,125 records in HEDB within only 167.06 seconds. As for defenses, we prove that authentication mechanisms, whether pre-query authentication or post-query authentication, are insufficient to defend against SARAs, which represent an inherent vulnerability within HEDB systems.
| Original language | English |
|---|---|
| Article number | 11126944 |
| Pages (from-to) | 7680-7693 |
| Number of pages | 14 |
| Journal | IEEE Transactions on Dependable and Secure Computing |
| Volume | 22 |
| Issue number | 6 |
| DOIs | |
| Publication status | Published - Aug 2025 |
Keywords
- database administrators
- Encrypted databases
- substitution and replay attacks
ASJC Scopus subject areas
- General Computer Science
- Electrical and Electronic Engineering
Fingerprint
Dive into the research topics of 'SARAs: Substitution and Replay Attacks in the Maintenance Mode of Encrypted Databases'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver