Plaintext Recovery Against Post-Filtering Access Control

📅 2026-08-12
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
While existing post-filtering–based fine-grained access control (FGAC) mechanisms prevent direct data leakage, their susceptibility to existence side channels poses significant risks under complex queries. This work presents the first systematic demonstration of how timing and scoring side channels, combined with rich query interfaces—such as range, prefix, and conjunctive predicates—can be exploited to efficiently reconstruct high-entropy plaintext content in PostgreSQL and Elasticsearch/OpenSearch. By leveraging binary search, SQL expressions, prefix expansion, and document scoring mechanisms, we devise novel reconstruction attacks tailored to relational databases and search engines, successfully recovering unknown attribute values, complete records, and corpus n-grams. Our findings expose fundamental security flaws in current post-filtering FGAC schemes when deployed in environments supporting expressive query predicates.
📝 Abstract
Fine-grained access control (FGAC) mechanisms such as row-level security (RLS) and document-level security (DLS) are widely deployed in databases to restrict access to data stored in physical indexing structures shared by multiple users (e.g., in multi-tenant databases, or in the implementation of least-privilege within an organization). FGAC implementations often use post-filtering where untrusted queries run over all data and private results are redacted afterwards. Prior work shows this approach can lead to side-channels that enable attackers to test if a chosen value exists in unseen data. While damaging, prior attacks do not enable the efficient recovery of rich, high-entropy data like full records or text documents. We show these side-channels are more damaging than previously thought. Using rich query interfaces (e.g., range, prefix, and conjunctive predicates), we amplify existence leakage into reconstruction attacks. We do this in two settings: - PostgreSQL (RLS timing). We exploit a timing side-channel and expressive SQL queries (e.g., ranges, conjunctions) to enumerate unknown attribute values and, in turn, full records via binary search over large domains. - Elasticsearch/OpenSearch (DLS scoring). We exploit scoring and prefix-expansion side-channels to recover indexed terms from documents. In some cases, we can extract $n$-grams in the corpus to recover approximate text. Our results show that FGAC side-channels must be evaluated in the presence of rich predicates, which can turn membership tests into scalable reconstruction of high-entropy records.
Problem

Research questions and friction points this paper is trying to address.

plaintext recovery
fine-grained access control
side-channel attack
post-filtering
data reconstruction
Innovation

Methods, ideas, or system contributions that make the work stand out.

side-channel attack
fine-grained access control
post-filtering
data reconstruction
query-based inference
🔎 Similar Papers
No similar papers found.