首页> 外文期刊>IEEE transactions on dependable and secure computing >Multi-CDN: Towards Privacy in Content Delivery Networks
【24h】

Multi-CDN: Towards Privacy in Content Delivery Networks

机译:多CDN:在内容交付网络中实现隐私

获取原文
获取原文并翻译 | 示例

摘要

A Content Delivery Network (CDN) is a distributed system composed of a large number of nodes that allows users to request objects from nearby nodes. CDN not only reduces end-to-end latency on the user side but also offloads Content Providers (CPs), providing resilience against Distributed Denial of Service (DDoS) attacks. However, by caching objects and processing user requests, CDN providers could infer user preferences and the popularity of objects, thus resulting in information leakage. Unfortunately, such information leakage may result in loss of user privacy and reveal business-specific information to untrusted or compromised CDN providers. State-of-the-art solutions can protect the content of sensitive objects but cannot prevent CDN providers from inferring user preferences and the popularity of objects. In this work, we present a privacy-preserving encrypted CDN system to hide not only the content of objects and user requests, but also protect user preferences and the popularity of objects from curious CDN providers. We employ encryption to protect the objects and user requests in a way that both the CDNs and CPs can perform the search operations without accessing objects and requests in cleartext. Our proposed system is based on a scalable key management approach for multi-user access, where no key regeneration and data re-encryption are needed for user revocation. We have implemented a prototype of the system and show its practical efficiency.
机译:内容传递网络(CDN)是由大量节点组成的分布式系统,允许用户从附近节点请求对象。 CDN不仅降低了用户端的端到端延迟,还卸载了内容提供商(CPS),为分布式拒绝服务(DDOS)攻击提供弹性。然而,通过缓存对象和处理用户请求,CDN提供程序可以推断用户偏好和对象的普及,从而导致信息泄漏。不幸的是,这种信息泄漏可能导致用户隐私丢失,并将特定于业务信息展示给不受信任或受损的CDN提供商。最先进的解决方案可以保护敏感对象的内容,但不能阻止CDN提供商推断用户偏好和对象的普及。在这项工作中,我们展示了一个隐私保留的加密CDN系统,不仅隐藏对象和用户请求的内容,还可以保护用户偏好以及来自好奇CDN提供程序的对象的普及。我们采用加密以防止对象和用户请求,以便CDN和CPS都可以执行搜索操作而不访问ClearText中的对象和请求。我们所提出的系统基于用于多用户访问的可扩展密钥管理方法,其中用户撤销不需要重新生成和数据重新加密。我们已经实施了该系统的原型并显示了其实际效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号