{"title":"Secure Dynamic SSE via Access Indistinguishable Storage","authors":"Tianhao Wang, Yunlei Zhao","doi":"10.1145/2897845.2897884","DOIUrl":null,"url":null,"abstract":"Cloud storage services such as Dropbox [1] and Google Drive [2] are becoming more and more popular. On the one hand, they provide users with mobility, scalability, and convenience. However, privacy issues arise when the storage becomes not fully controlled by users. Although modern encryption schemes are effective at protecting content of data, there are two drawbacks of the encryption-before-outsourcing approach: First, one kind of sensitive information, Access Pattern of the data is left unprotected. Moreover, encryption usually makes the data difficult to use. In this paper, we propose AIS (Access Indistinguishable Storage), the first client-side system that can partially conceal access pattern of the cloud storage in constant time. Besides data content, AIS can conceal information about the number of initial files, and length of each initial file. When it comes to the access phase after initiation, AIS can effectively conceal the behavior (read or write) and target file of the current access. Moreover, the existence and length of each file will remain confidential as long as there is no access after initiation. One application of AIS is SSE (Searchable Symmetric Encryption), which makes the encrypted data searchable. Based on AIS, we propose SBA (SSE Built on AIS). To the best of our knowledge, SBA is safer than any other SSE systems of the same complexity, and SBA is the first to conceal whether current keyword was queried before, the first to conceal whether current operation is an addition or deletion, and the first to support direct modification of files.","PeriodicalId":166633,"journal":{"name":"Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security","volume":"227 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2897845.2897884","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Cloud storage services such as Dropbox [1] and Google Drive [2] are becoming more and more popular. On the one hand, they provide users with mobility, scalability, and convenience. However, privacy issues arise when the storage becomes not fully controlled by users. Although modern encryption schemes are effective at protecting content of data, there are two drawbacks of the encryption-before-outsourcing approach: First, one kind of sensitive information, Access Pattern of the data is left unprotected. Moreover, encryption usually makes the data difficult to use. In this paper, we propose AIS (Access Indistinguishable Storage), the first client-side system that can partially conceal access pattern of the cloud storage in constant time. Besides data content, AIS can conceal information about the number of initial files, and length of each initial file. When it comes to the access phase after initiation, AIS can effectively conceal the behavior (read or write) and target file of the current access. Moreover, the existence and length of each file will remain confidential as long as there is no access after initiation. One application of AIS is SSE (Searchable Symmetric Encryption), which makes the encrypted data searchable. Based on AIS, we propose SBA (SSE Built on AIS). To the best of our knowledge, SBA is safer than any other SSE systems of the same complexity, and SBA is the first to conceal whether current keyword was queried before, the first to conceal whether current operation is an addition or deletion, and the first to support direct modification of files.
Dropbox[1]和Google Drive[2]等云存储服务越来越受欢迎。一方面,它们为用户提供了移动性、可扩展性和便利性。但是,当存储不完全由用户控制时,就会出现隐私问题。尽管现代加密方案在保护数据内容方面是有效的,但这种先加密后外包的方法存在两个缺点:首先,一类敏感信息,即数据的访问模式没有得到保护。此外,加密通常会使数据难以使用。在本文中,我们提出了AIS (Access ininguishable Storage),这是第一个能够在恒定时间内部分隐藏云存储访问模式的客户端系统。除了数据内容外,AIS还可以隐藏初始文件的数量和每个初始文件的长度等信息。在启动后的访问阶段,AIS可以有效地隐藏当前访问的行为(读或写)和目标文件。此外,只要启动后没有访问,每个文件的存在和长度将保持机密。AIS的一个应用是SSE(可搜索对称加密),它使加密的数据可搜索。基于AIS,我们提出了SBA (SSE Built on AIS)。据我们所知,SBA比其他相同复杂度的SSE系统更安全,SBA是第一个隐藏当前关键字之前是否被查询过,第一个隐藏当前操作是添加还是删除,第一个支持直接修改文件的系统。