A Security Proxy to Cloud Storage Backends Based on an Efficient Wildcard Searchable Encryption

Shen-Ming Chung, Ming-Der Shieh, T. Chiueh
{"title":"A Security Proxy to Cloud Storage Backends Based on an Efficient Wildcard Searchable Encryption","authors":"Shen-Ming Chung, Ming-Der Shieh, T. Chiueh","doi":"10.1109/SC2.2018.00026","DOIUrl":null,"url":null,"abstract":"Cloud storage backends such as Amazon S3 are a potential storage solution to enterprises. However, to couple enterprises with these backends, at least two problems must be solved: first, how to make these semi-trusted backends as secure as on-premises storage; and second, how to selectively retrieve files as easy as on-premises storage. A security proxy can address both the problems by building a local index from keywords in files before encrypting and uploading files to these backends. But, if the local index is built in plaintext, file content is still vulnerable to local malicious staff. Searchable Encryption (SE) can get rid of this vulnerability by making index into ciphertext; however, its known constructions often require modifications to index database, and, to support wildcard queries, they are not efficient at all. In this paper, we present a security proxy that, based on our wildcard SE construction, can securely and efficiently couple enterprises with these backends. In particular, since our SE construction can work directly with existing database systems, it incurs only a little overhead, and when needed, permits the security proxy to run with constantly small storage footprint by readily out-sourcing all built indices to existing cloud databases.","PeriodicalId":340244,"journal":{"name":"2018 IEEE 8th International Symposium on Cloud and Service Computing (SC2)","volume":"23 3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE 8th International Symposium on Cloud and Service Computing (SC2)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SC2.2018.00026","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Cloud storage backends such as Amazon S3 are a potential storage solution to enterprises. However, to couple enterprises with these backends, at least two problems must be solved: first, how to make these semi-trusted backends as secure as on-premises storage; and second, how to selectively retrieve files as easy as on-premises storage. A security proxy can address both the problems by building a local index from keywords in files before encrypting and uploading files to these backends. But, if the local index is built in plaintext, file content is still vulnerable to local malicious staff. Searchable Encryption (SE) can get rid of this vulnerability by making index into ciphertext; however, its known constructions often require modifications to index database, and, to support wildcard queries, they are not efficient at all. In this paper, we present a security proxy that, based on our wildcard SE construction, can securely and efficiently couple enterprises with these backends. In particular, since our SE construction can work directly with existing database systems, it incurs only a little overhead, and when needed, permits the security proxy to run with constantly small storage footprint by readily out-sourcing all built indices to existing cloud databases.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于高效通配符可搜索加密的云存储后端安全代理
云存储后端(如Amazon S3)是企业的潜在存储解决方案。然而,要将企业与这些后端结合起来,至少必须解决两个问题:首先,如何使这些半可信的后端与本地存储一样安全;其次,如何有选择地检索文件,就像本地存储一样简单。安全代理可以通过在加密和上传文件到这些后端之前根据文件中的关键字构建本地索引来解决这两个问题。但是,如果以明文形式构建本地索引,则文件内容仍然容易受到本地恶意人员的攻击。可搜索加密(seable Encryption, SE)可以通过将索引转化为密文来解决这一问题;然而,它的已知结构通常需要修改索引数据库,并且为了支持通配符查询,它们的效率很低。在本文中,我们提出了一个安全代理,该代理基于我们的通配符SE结构,可以安全有效地将企业与这些后端连接起来。特别是,由于我们的SE构造可以直接与现有的数据库系统一起工作,因此它只会产生很少的开销,并且在需要时,通过将所有构建的索引外包给现有的云数据库,允许安全代理以持续较小的存储占用运行。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Get Your Head Out of the Clouds: The Illusion of Confidentiality & Privacy Improving the Performance of Stock Trend Prediction by Applying GA to Feature Selection Publisher's Information SC2 2018 Program Committee Hera Object Storage: A Seamless, Automated Multi-Tiering Solution on Top of OpenStack Swift
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1