Search papers, labs, and topics across Lattice.
This paper investigates the vulnerabilities of fine-grained access control (FGAC) mechanisms, specifically focusing on post-filtering methods in databases like PostgreSQL and Elasticsearch. By leveraging rich query interfaces, the authors reveal that existing side-channel attacks can be amplified to efficiently reconstruct high-entropy data, such as full records and text documents, which was previously thought to be infeasible. Their findings indicate that FGAC implementations must be critically assessed under these conditions, as they expose sensitive information more severely than recognized in prior research.
Side-channel attacks on FGAC can now reconstruct high-entropy data, revealing a critical vulnerability in widely used database security mechanisms.
Fine-grained access control (FGAC) mechanisms such as row-level security (RLS) and document-level security (DLS) are widely deployed in databases to restrict access to data stored in physical indexing structures shared by multiple users (e.g., in multi-tenant databases, or in the implementation of least-privilege within an organization). FGAC implementations often use post-filtering where untrusted queries run over all data and private results are redacted afterwards. Prior work shows this approach can lead to side-channels that enable attackers to test if a chosen value exists in unseen data. While damaging, prior attacks do not enable the efficient recovery of rich, high-entropy data like full records or text documents. We show these side-channels are more damaging than previously thought. Using rich query interfaces (e.g., range, prefix, and conjunctive predicates), we amplify existence leakage into reconstruction attacks. We do this in two settings: - PostgreSQL (RLS timing). We exploit a timing side-channel and expressive SQL queries (e.g., ranges, conjunctions) to enumerate unknown attribute values and, in turn, full records via binary search over large domains. - Elasticsearch/OpenSearch (DLS scoring). We exploit scoring and prefix-expansion side-channels to recover indexed terms from documents. In some cases, we can extract $n$-grams in the corpus to recover approximate text. Our results show that FGAC side-channels must be evaluated in the presence of rich predicates, which can turn membership tests into scalable reconstruction of high-entropy records.