【24h】

Rekeying for Encrypted Deduplication Storage

机译:重新加密加密的重复数据删除存储

获取原文

摘要

Rekeying refers to an operation of replacing an existing key with a new key for encryption. It renews security protection, so as to protect against key compromise and enable dynamic access control in cryptographic storage. However, it is non-trivial to realize efficient rekeying in encrypted deduplication storage systems, which use deterministic content-derived encryption keys to allow deduplication on ciphertexts. We design and implement REED, a rekeying-aware encrypted deduplication storage system. REED builds on a deterministic version of all-or-nothing transform (AONT), such that it enables secure and lightweight rekeying, while preserving the deduplication capability. We propose two REED encryption schemes that trade between performance and security, and extend REED for dynamic access control. We implement a REED prototype with various performance optimization techniques. Our trace-driven testbed evaluation shows that our REED prototype maintains high performance and storage efficiency.
机译:密钥更新是指用新密钥替换现有密钥以进行加密的操作。它更新了安全保护,以防止密钥泄露并启用密码存储中的动态访问控制。但是,在加密的重复数据删除存储系统中实现高效的密钥更新并非易事,该系统使用确定性的内容派生的加密密钥来允许对密文进行重复数据删除。我们设计并实现REED,这是一种可识别密钥更新的重复数据删除存储系统。 REED建立在全有或全无转换(AONT)的确定性版本的基础上,因此它可以实现安全轻便的密钥更新,同时保留重复数据删除功能。我们提出了两种在性能和安全性之间进行权衡的REED加密方案,并扩展了REED以进行动态访问控制。我们使用各种性能优化技术来实现REED原型。我们的跟踪驱动测试台评估表明,我们的REED原型保持了高性能和存储效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号