The Mastermind Attack on Genomic Data

被引:29
作者
Goodrich, Michael T. [1 ]
机构
[1] Univ Calif Irvine, Dept Comp Sci, Secure Comp & Networking Ctr, Irvine, CA 92717 USA
来源
PROCEEDINGS OF THE 2009 30TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY | 2009年
关键词
mitochondrial DNA; genomic databases; privacy; mastermind; attacks; SEQUENCE; MITOMAP; DNA;
D O I
10.1109/SP.2009.4
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper we study the degree to which a genomic string, Q, leaks details about itself any time it engages in comparison protocols with a genomic querier Bob, even if those protocols are cryptographically guaranteed to produce no additional information other than the scores that assess the degree to which Q matches strings offered by Bob. We show that such scenarios allow Bob to play variants of the game of Mastermind with Q so as to learn the complete identity of Q. We show that there are a number of efficient implementations for Bob to employ in these Mastermind attacks, depending on knowledge he has about the structure of Q, which show how quickly he can determine Q. Indeed, we show that Bob can discover Q using a number of rounds of test comparisons that is much smaller than the length of Q, under various assumptions regarding the types of scores that are returned by the cryptographic protocols and whether he can use knowledge about the distribution that Q comes from, e.g., using public knowledge about the properties of human DNA. We also provide the results of an experimental study we performed on a database of mitochondrial DNA, showing the vulnerability of existing real-world DNA data to the Mastermind attack.
引用
收藏
页码:204 / 218
页数:15
相关论文
共 40 条
[1]  
AHO AV, 1976, J ACM, V23, P1, DOI 10.1145/321921.321922
[2]  
AMIRBEKYAN A, 2007, AUSDM 07
[3]  
[Anonymous], 1990, Cryptology and Computational Number Theory, DOI 10.1090/psapm/042
[4]  
[Anonymous], 1979, Computers and Intractablity: A Guide to the Theory of NP-Completeness
[5]  
[Anonymous], MOL SYSTEMS BIOL
[6]  
[Anonymous], 2005, INT J INF SECUR, DOI DOI 10.1007/S10207-005-0070-3
[7]  
[Anonymous], P NETW DISTR SYST SE
[8]  
ATALLAH MJ, 2003, WPES 03, P39
[9]   Lossless compression of chemical fingerprints using integer entropy codes improves storage and retrieval [J].
Baldi, Pierre ;
Benz, Ryan W. ;
Hirschberg, Daniel S. ;
Swamidass, S. Joshua .
JOURNAL OF CHEMICAL INFORMATION AND MODELING, 2007, 47 (06) :2098-2109
[10]   The genographic project public participation mitochondrial DNA database [J].
Behar, Doron M. ;
Rosset, Saharon ;
Blue-Smith, Jason ;
Balanovsky, Oleg ;
Tzur, Shay ;
Comas, David ;
Mitchell, R. John ;
Quintana-Murci, Lluis ;
Tyler-Smith, Chris ;
Wells, R. Spencer .
PLOS GENETICS, 2007, 3 (06) :1083-1095