首页> 外文期刊>IEEE transactions on dependable and secure computing >Towards Thwarting Template Side-Channel Attacks in Secure Cloud Deduplications
【24h】

Towards Thwarting Template Side-Channel Attacks in Secure Cloud Deduplications

机译:在挫败模板侧通道攻击中的安全云重复保险

获取原文
获取原文并翻译 | 示例
           

摘要

As one of a few critical technologies to cloud storage service, deduplication allows cloud servers to save storage space by deleting redundant file copies. However, it often leaks side channel information regarding whether an uploading file gets deduplicated or not. Exploiting this information, adversaries can easily launch a template side-channel attack and severely harm cloud users' privacy. To thwart this kind of attack, we resort to the k-anonymity privacy concept to design secure threshold deduplication protocols. Specifically, we have devised a novel cryptographic primitive called "dispersed convergent encryption" (DCE) scheme, and proposed two different constructions of it. With these DCE schemes, we successfully construct secure threshold deduplication protocols that do not rely on any trusted third party. Our protocols not only support confidentiality protections and ownership verifications, but also enjoy formal security guarantee against template side-channel attacks even when the cloud server could be a "covert adversary" who may violate the predefined threshold and perform deduplication covertly. Experimental evaluations show our protocols enjoy very good performance in practice.
机译:作为云存储服务的一些关键技术之一,重复数据删除允许云服务器通过删除冗余文件副本来保存存储空间。然而,它经常泄漏关于上传文件是否删除的侧信道信息。利用这些信息,对手可以轻松推出模板侧渠攻击并严重损害云用户的隐私。为了挫败这种攻击,我们求助于k-匿名隐私概念来设计安全的阈值重复数据删除协议。具体而言,我们设计了一种名为“分散的收敛加密”(DCE)方案的新型加密原语,并提出了两个不同的结构。使用这些DCE方案,我们成功构建了不依赖于任何可信第三方的安全阈值重复数据删除协议。我们的协议不仅支持机密性保护和所有权验证,而且也享有正式的安全保障,即使云服务器可能是可能违反预定阈值并执行重复数据删除的“隐蔽对手”,也可以享受对模板侧通道攻击的正式安全保障。实验评估表明我们的协议在实践中享有非常好的表现。

著录项

  • 来源
  • 作者单位

    Nanjing Univ State Key Lab Novel Software Technol Nanjing 210023 Peoples R China|Nanjing Univ Comp Sci & Technol Dept Nanjing 210023 Peoples R China;

    Nanjing Univ State Key Lab Novel Software Technol Nanjing 210023 Peoples R China|Nanjing Univ Comp Sci & Technol Dept Nanjing 210023 Peoples R China;

    Nanjing Univ State Key Lab Novel Software Technol Nanjing 210023 Peoples R China|Nanjing Univ Comp Sci & Technol Dept Nanjing 210023 Peoples R China;

    Nanjing Univ State Key Lab Novel Software Technol Nanjing 210023 Peoples R China|Nanjing Univ Comp Sci & Technol Dept Nanjing 210023 Peoples R China;

    Nanjing Univ State Key Lab Novel Software Technol Nanjing 210023 Peoples R China|Nanjing Univ Comp Sci & Technol Dept Nanjing 210023 Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Servers; Protocols; Cloud computing; Privacy; Encryption; Side-channel attacks; Cloud; secure deduplication; privacy; proofs of ownership;

    机译:服务器;协议;云计算;隐私;加密;侧通道攻击;云;安全重复数据删除;隐私;所有权证明;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号