首页> 外文会议>IEEE Conference on Communications and Network Security >EncFS goes multi-user: Adding access control to an encrypted file system
【24h】

EncFS goes multi-user: Adding access control to an encrypted file system

机译:EncFS可以成为多用户:将访问控制添加到加密的文件系统

获取原文

摘要

Among the different existing cryptographic file systems, EncFS has a unique feature that makes it attractive for backup setups involving untrusted (cloud) storage. It is a file-based overlay file system in normal operation (i.e., it maintains a directory hierarchy by storing encrypted representations of files and folders in a specific source folder), but its reverse mode allows to reverse this process: Users can mount deterministic, encrypted views of their local, unencrypted files on the fly, allowing synchronization to untrusted storage using standard tools like rsync without having to store encrypted representations on the local hard drive. So far, EncFS is a single-user solution: All files of a folder are encrypted using the same, static key; file access rights are passed through to the encrypted representation, but not otherwise considered. In this paper, we work out how multi-user support can be integrated into EncFS and its reverse mode in particular. We present an extension that a) stores individual files' owner/group information and permissions in a confidential and authenticated manner, and b) cryptographically enforces thereby specified read rights. For this, we introduce user-specific keys and an appropriate, automatic key management. Given a user's key and a complete encrypted source directory, the extension allows access to exactly those files the user is authorized for according to the corresponding owner/group/permissions information. Just like EncFS, our extension depends only on symmetric cryptographic primitives.
机译:在不同的现有加密文件系统中,EncFS具有独特的功能,使其对于涉及不可信(云)存储的备份设置具有吸引力。它是正常运行中的基于文件的覆盖文件系统(即,它通过将文件和文件夹的加密表示存储在特定的源文件夹中来维护目录层次结构),但是其反向模式可以逆转此过程:用户可以进行确定性安装,实时查看其本地未加密文件的加密视图,从而允许使用rsync之类的标准工具同步到不受信任的存储,而不必在本地硬盘驱动器上存储加密的表示形式。到目前为止,EncFS是单用户解决方案:文件夹的所有文件都使用相同的静态密钥加密;文件访问权限会传递给加密表示,但不会另外考虑。在本文中,我们研究了如何将多用户支持集成到EncFS中,尤其是它的反向模式。我们提供了一个扩展,即a)以机密且经过身份验证的方式存储单个文件的所有者/组信息和权限,并且b)以此密码方式强制执行指定的读取权限。为此,我们介绍了用户特定的密钥和适当的自动密钥管理。给定用户的密钥和完整的加密源目录,该扩展名允许根据相应的所有者/组/权限信息准确访问用户被授权访问的那些文件。就像EncFS一样,我们的扩展仅依赖于对称密码基元。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号