DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Quentin Lefebvre <qlefebvre_pro@yahoo.com>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] Impossible task ?
Date: Tue, 16 Dec 2014 23:26:11 +0100	[thread overview]
Message-ID: <5490B183.80900@yahoo.com> (raw)
In-Reply-To: <20141216155850.GA736@tansi.org>

There are some "order preserving encryption" (OPE) schemes, but they are 
less secure.
And indeed, it's not cryptsetup-related.

I guess you should find something about that on Internet.

Best regards,
Quentin

Le 16/12/2014 16:58, Arno Wagner a écrit :
> Hi,
>
> not really a topic for this list, but I will answer anyways.
>
> No, you cannot do this. Proof idea: If you can do lookup,
> you can break the encryption by checking whether a person is
> in there via the lookup functionality.
>
> Sure, if you only allow proper partial names, the attacker
> does not get the last character of the name, but that does
> not help much. There are not enough names in the world to
> make this attack too costly, and the attacker can do it
> character-by-character by using longer and longer partial
> names.
>
> The thing is that the possibility of lookup directly
> implies the data is _not_ protected against reading it.
>
> Gr"usse,
> Arno
>
>
> On Tue, Dec 16, 2014 at 13:22:17 CET, bill wrote:
>> I have conflicting needs and fear that they may be unresolvable.
>> I. I need to store patient names (3 fields: last, first, middle
>> initial) with the first and last names encrypted.
>> 2. I need to be able to do partial name lookups if the user enters a
>> partial first or last name.
>>
>> I presume that after encryption the names are no longer in
>> alphabetical order, so looking up using an encrypted partial name
>> will not result in a set of names beginning with that partial name.
>>
>> Is there an approach to this, or need I go back to my boss and
>> suggest "plan B."
>>
>> --
>> Bill Drescher
>> william {at} TechServSys {dot} com
>>
>
>> _______________________________________________
>> dm-crypt mailing list
>> dm-crypt@saout.de
>> http://www.saout.de/mailman/listinfo/dm-crypt
>
>

      reply	other threads:[~2014-12-16 22:26 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-12-16 12:22 [dm-crypt] Impossible task ? bill
2014-12-16 15:58 ` Arno Wagner
2014-12-16 22:26   ` Quentin Lefebvre [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5490B183.80900@yahoo.com \
    --to=qlefebvre_pro@yahoo.com \
    --cc=dm-crypt@saout.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox