Side channel attack on a partially encrypted MPEG-G file

New genome sequencing technologies have decreased the cost of generating genomic data, thus increasing storage needs. The International Organization for Standardization (ISO) working group MPEG has developed a standard for genomic data compression with encryption features. The approach taken in stan...

Full description

Bibliographic Details
Authors: Naro, Daniel|||0000-0003-3114-1298, Delgado Mercè, Jaime|||0000-0003-1366-663X, Llorente Viejo, Silvia|||0000-0003-2000-6912
Format: article
Publication Date:2021
Country:España
Institution:Universitat Politècnica de Catalunya (UPC)
Repository:UPCommons. Portal del coneixement obert de la UPC
Language:English
OAI Identifier:oai:upcommons.upc.edu:2117/342757
Online Access:https://hdl.handle.net/2117/342757
https://dx.doi.org/10.1007/s11042-021-10720-7
Access Level:Open access
Keyword:Data encryption (Computer science)
Data compression (Computer science)
Genomics
Encryption
Genomic information
Information leakage
MPEG-G
Xifratge (Informàtica)
Dades -- Compressió (Informàtica)
Genòmica
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica::Criptografia
Àrees temàtiques de la UPC::Informàtica::Aplicacions de la informàtica::Bioinformàtica
Description
Summary:New genome sequencing technologies have decreased the cost of generating genomic data, thus increasing storage needs. The International Organization for Standardization (ISO) working group MPEG has developed a standard for genomic data compression with encryption features. The approach taken in standard MPEG-G (ISO/IEC 23092) to compress genomic information was to group similar data into streams. Taking this into account, one of the protection options considered was to encrypt each stream separately. In this paper, we show that an attacker can use an unencrypted stream to deduce the encrypted content if streams are encrypted separately. To do so, we present two different attacks, one based on signal processing and the other one based on neural networks. The signal-based attack only works with unrealistic settings, whereas the neural network-based one recovers data with realistic settings (regarding read length and coverage). The presented results made MPEG reconsider the encryption strategy, before final publication of the standard, discarding separate streams encryption approach.