UTRA: Universal Token Reusability Attack and Token Unforgeable Delegatable Order-Revealing Encryption

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

As datasets grow, users increasingly rely on cloud services for data storage and processing. Consequently, concerns regarding data protection and the practical use of encrypted data have emerged as significant challenges. One promising solution is order-revealing encryption (ORE), which enables efficient operations on encrypted numerical data. To support distributed environments with different users, delegatable ORE (DORE) extends this functionality to multi-client settings, enabling order comparisons between ciphertexts encrypted under different secret keys. However, Hahn et al. proposed a token forgery attack against DORE with a threat model and introduced the secure DORE (SEDORE) scheme as a countermeasure. Despite this enhancement, we claim that SEDORE remains vulnerable under the same threat model. In this paper, we present a novel Universal Token Reusability Attack, which exposes a critical vulnerability in SEDORE with the identical threat model. To mitigate this, we introduce the concept of verifiable delegatable order-revealing encryption (VDORE), along with a formal definition of token unforgeability. Building on this, we design a new scheme, Token Unforgeable DORE (TUDORE), which ensures token unforgeability. Moreover, TUDORE achieves 1.5× faster token generation than SEDORE with enhanced security. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

키워드

Cross-database systemOrder-revealing encryptionToken-based authenticationAuthenticationCryptographyDigital storageDistributed database systems
제목
UTRA: Universal Token Reusability Attack and Token Unforgeable Delegatable Order-Revealing Encryption
저자
Park, JaehwanLee, HyeonbumHur, JunbeomSeo, Jae HongKim, Doowon
DOI
10.1007/978-3-032-07891-9_17
발행일
2026-00
유형
Proceedings Paper
저널명
Lecture Notes in Computer Science
16054 LNCS
페이지
321 ~ 340