Enabling Privacy-Preserving Header Matching for Outsourced Middleboxes

被引:0
|
作者
Guo, Yu [1 ]
Wang, Cong [1 ]
Yuan, Xingliang [2 ]
Jia, Xiaohua [1 ]
机构
[1] City Univ Hong Kong, Hong Kong, Peoples R China
[2] Monash Univ, Melbourne, Vic, Australia
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Over the past few years, enterprises start adopting software middlebox services from cloud or NFV service providers. Although this new service model is recognized to be cost-effective and scalable for traffic processing, privacy concerns arise because of traffic redirection to outsourced middleboxes. To ease these concerns, recent efforts are made to design secure middlebox services that can directly function over encrypted traffic and middlebox rules. But prior designs only work for portions of frequently-used network functions. To push forward this area, in this work, we investigate header matching based functions like firewall filtering and packet classification. To enable privacy-preserving processing on encrypted packets, we start from the latest primitive "order-revealing encryption (ORE)" for encrypted range search. In particular, we devise a new practical ORE construction tailored for network functions. The advantages include: 1) guaranteed protection of packet headers and rule specified ranges; 2) reduced accessible information during comparisons; 3) rule-aware size reduction for ORE ciphertexts. We implement a fully functional system prototype and deploy it at Microsoft Azure Cloud. Evaluation results show that our system can achieve per packet matching latency 0.53 to 15.87 millisecond over 1.6K firewall rules.
引用
下载
收藏
页数:10
相关论文
共 50 条
  • [31] Outsourced privacy-preserving classification service over encrypted data
    Li, Tong
    Huang, Zhengan
    Li, Ping
    Liu, Zheli
    Jia, Chunfu
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 106 : 100 - 110
  • [32] Privacy-Preserving Computation and Verification of Aggregate Queries on Outsourced Databases
    Thompson, Brian
    Haber, Stuart
    Horne, William G.
    Sander, Tomas
    Yao, Danfeng
    PRIVACY ENHANCING TECHNOLOGIES, PROCEEDINGS, 2009, 5672 : 185 - +
  • [33] Outsourced Privacy-Preserving Data Alignment on Vertically Partitioned Database
    Wang, Zhuzhu
    Hu, Cui
    Xiao, Bin
    Liu, Yang
    Li, Teng
    Ma, Zhuo
    Ma, Jianfeng
    IEEE TRANSACTIONS ON BIG DATA, 2023, 9 (05) : 1408 - 1419
  • [34] Privacy-preserving biometric verification with outsourced correlation filter computation
    Taheri, Motahareh
    Mozaffari, Saeed
    Keshavarzi, Parviz
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (14) : 21425 - 21448
  • [35] An Efficient Privacy-Preserving Outsourced Calculation Toolkit With Multiple Keys
    Liu, Ximeng
    Deng, Robert H.
    Choo, Kim-Kwang Raymond
    Weng, Jian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (11) : 2401 - 2414
  • [36] Optimizing Privacy-Preserving Outsourced Convolutional Neural Network Predictions
    Li, Minghui
    Chow, Sherman S. M.
    Hu, Shengshan
    Yan, Yuejing
    Shen, Chao
    Wang, Qian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (03) : 1592 - 1604
  • [37] Enabling Privacy-preserving Auctions in Big Data
    Jung, Taeho
    Li, Xiang-Yang
    2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2015, : 173 - 178
  • [38] DIMY: Enabling privacy-preserving contact tracing
    Ahmed, Nadeem
    Michelin, Regio A.
    Xue, Wanli
    Putra, Guntur Dharma
    Ruj, Sushmita
    Kanhere, Salil S.
    Jha, Sanjay
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 202
  • [39] Privacy-Preserving Frequent Itemset Mining in Outsourced Transaction Databases
    Chandrasekharan, Iyer
    Baruah, P. K.
    Mukkamala, Ravi
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2015, : 787 - 793
  • [40] Privacy-Preserving Outsourced Clinical Decision Support System in the Cloud
    Liu, Ximeng
    Deng, Robert H.
    Choo, Kim-Kwang Raymond
    Yang, Yang
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (01) : 222 - 234