首页> 外文期刊>Cloud Computing, IEEE Transactions on >Securing Cloud Data Under Key Exposure
【24h】

Securing Cloud Data Under Key Exposure

机译:在关键暴露下保护云数据

获取原文
获取原文并翻译 | 示例
       

摘要

Recent news reveal a powerful attacker which breaks data confidentiality by acquiring cryptographic keys, by means of coercion or backdoors in cryptographic software. Once the encryption key is exposed, the only viable measure to preserve data confidentiality is to limit the attacker's access to the ciphertext. This may be achieved, for example, by spreading ciphertext blocks across servers in multiple administrative domains-thus assuming that the adversary cannot compromise all of them. Nevertheless, if data is encrypted with existing schemes, an adversary equipped with the encryption key, can still compromise a single server and decrypt the ciphertext blocks stored therein. In this paper, we study data confidentiality against an adversary which knows the encryption key and has access to a large fraction of the ciphertext blocks. To this end, we propose Bastion, a novel and efficient scheme that guarantees data confidentiality even if the encryption key is leaked and the adversary has access to almost all ciphertext blocks. We analyze the security of Bastion, and we evaluate its performance by means of a prototype implementation. We also discuss practical insights with respect to the integration of Bastion in commercial dispersed storage systems. Our evaluation results suggest that Bastion is well-suited for integration in existing systems since it incurs less than 5 percent overhead compared to existing semantically secure encryption modes.
机译:最近的新闻显示,一个强大的攻击者可以通过强制性或加密软件中的后门程序,通过获取加密密钥来破坏数据机密性。一旦暴露了加密密钥,保存数据机密性的唯一可行措施就是限制攻击者对密文的访问。例如,可以通过在多个管理域中的服务器之间分布密文块来实现此目的,从而假设对手无法破坏所有密文。但是,如果使用现有方案对数据进行加密,则配备有加密密钥的对手仍然可以破坏单个服务器并解密其中存储的密文块。在本文中,我们针对知道加密密钥并可以访问大部分密文块的对手研究数据机密性。为此,我们提出了Bastion,这是一种新颖而有效的方案,即使加密密钥泄漏并且对手可以访问几乎所有密文块,也可以保证数据的机密性。我们分析堡垒的安全性,并通过原型实现评估其性能。我们还将讨论有关堡垒在商业分散存储系统中集成的实践见解。我们的评估结果表明,Bastion非常适合在现有系统中进行集成,因为与现有的语义安全加密模式相比,Bastion的开销不到5%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号