首页> 外文期刊>Services Computing, IEEE Transactions on >Decentralized Server-Aided Encryption for Secure Deduplication in Cloud Storage
【24h】

Decentralized Server-Aided Encryption for Secure Deduplication in Cloud Storage

机译:云存储中安全重复数据删除的分散式服务器辅助加密

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud storage provides scalable and low cost resources featuring economies of scale based on multi-tenant architecture. As the amount of data outsourced grows explosively, data deduplication, a technique that eliminates data redundancy, becomes essential. However, deduplication leads to problems with data confidentiality, thereby necessitating secure deduplication solutions. Server-aided encryption schemes have been proposed to achieve the strongest confidentiality but with the cost of managing a key server (KS). Previous schemes, however, are based on a centralized KS that uses only a single secret key assuming a single KS in the system. In cloud storage where multi-tenancy and scalability are crucial, such schemes degrade not only the effectiveness of deduplication but also the scalability with increasing users. In this paper, we extend server-aided encryption to a decentralized setting that consists of multiple KSs. The key idea of our proposed scheme is to construct an inter-KS deduplication algorithm, by which a cloud storage service provider can perform deduplication over ciphertexts from different KSs within a tenant or across tenants. This way, our scheme simultaneously offers flexibility of KS management and cross-tenant deduplication over encrypted data. The novelty of the approach is using a decentralized architecture that does not require any centralized entities for the coordination or pre-sharing of secrets among KSs. Therefore, it allows cloud storage services to offer high deduplication efficiency and scalability while preserving strong data confidentiality. We show the result of performance analysis on the proposed scheme by conducting extensive experiments. In addition, our security analysis demonstrate that the proposed scheme satisfies all desired security properties.
机译:云存储提供了基于多租户架构的规模经济的可扩展和低成本资源。随着数据的数量外包量大,数据重复数据删除,一种消除数据冗余的技术变得必不可少。但是,重复数据删除导致数据机密性问题,从而需要安全的重复数据删除解决方案。已经提出了服务器辅助加密方案来实现最强的机密性,但是管理密钥服务器(KS)的成本。然而,以前的方案基于集中式KS,该ks仅使用在系统中的单个ks中的单个秘密密钥。在多租户和可伸缩性至关重要的云存储中,这些方案不仅降低了重复数据删除的有效性,而且降低了与增加用户的可扩展性。在本文中,我们将服务器辅助加密扩展到由多个KSS组成的分散设置。我们所提出的方案的关键思想是构造一个KS重复数据删除算法,云存储服务提供商可以通过租户或租户中的不同KSS的密码上重复数据删除。这样,我们的方案同时提供了KS管理和跨租户重复数据删除的灵活性。该方法的新颖性是使用分散的架构,该架构不需要任何集中式实体进行KSS之间的协调或预先分享秘密。因此,它允许云存储服务提供高重复数据删除效率和可扩展性,同时保留强大的数据机密性。通过进行广泛的实验,我们展示了拟议方案的性能分析结果。此外,我们的安全分析表明,所提出的方案满足所有所需的安全性质。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号