首页> 外文会议>Cloud computing security workshop >On Protecting Integrity and Confidentiality of Cryptographic File System for Outsourced Storage
【24h】

On Protecting Integrity and Confidentiality of Cryptographic File System for Outsourced Storage

机译:关于保护加密储存加密文件系统的完整性和机密性

获取原文

摘要

A cryptographic network file system has to guarantee confidentiality and integrity of its files, and also it has to support random access. For this purpose, existing designs mainly rely on (often ad-hoc) combination of Merkle hash tree with a block cipher mode of encryption. In this paper, we propose a new design based on a MAC tree construction which uses a universal-hash based stateful MAC. This new design enables standard model security proof and also better performance compared with Merkle hash tree. We formally define the security notions for file encryption and prove that our scheme provides both confidentiality and integrity. We implement our scheme in coreFS, a user-level network file system, and evaluate the performance in comparison with the standard design. Experimental results confirm that our construction provides integrity protection at a smaller cost.
机译:加密网络文件系统必须保证其文件的机密性和完整性,并且还必须支持随机访问权限。为此目的,现有的设计主要依赖于(通常是ad-hoc)Merkle哈希树的组合,并具有块密码加密模式。在本文中,我们提出了一种基于MAC树施工的新设计,该设计使用了基于通用哈希的有状态MAC。与Merkle Hash树相比,这种新设计使标准模型安全证明以及更好的性能。我们正式定义文件加密的安全概念,并证明我们的计划提供了机密性和完整性。我们在Corefs,用户级网络文件系统中实现了我们的计划,并与标准设计相比评估性能。实验结果证实,我们的施工以较小的成本提供完整性保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号