RARE: Defeating Side Channels based on Data-Deduplication in Cloud Storage

被引:0
|
作者
Pooranian, Zahra [1 ]
Chen, Kang-Cheng [2 ]
Yu, Chia-Mu [3 ,4 ]
Conti, Mauro [1 ]
机构
[1] Univ Padua, Dept Math, Padua, Italy
[2] Yuan Ze Univ, Dept Comp Sci & Engn, Taoyuan, Taiwan
[3] Natl Chung Hsing Univ, Dept Comp Sci & Engn, Taichung, Taiwan
[4] Taiwan Informat Secur Ctr TWISC, Taipei, Taiwan
基金
欧盟地平线“2020”;
关键词
Cloud Storage; Data Deduplication; Data Privacy; Side Channel;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Client-side data deduplication enables cloud storage services (e.g., Dropbox) to achieve both storage and bandwidth savings, resulting in reduced operating cost and high level of user satisfaction. However, the deduplication checks (i.e., the corresponding essential message exchange) create a side channel, exposing the privacy of file existence status to the attacker. In particular, the binary response from the deduplication check reveals the information about the existence of a copy of the file in the cloud storage. This behavior can be exploited to launch further attacks such as learning the sensitive file content and establishing a covert channel. While current solutions provide only weaker privacy or rely on unreasonable assumptions, we propose RAndom REsponse (RARE) approach to achieve stronger privacy. The idea behind our proposed RARE solution is that the uploading user sends the deduplication request for two chunks at once. The cloud receiving the deduplication request returns the randomized deduplication response with the careful design so as to preserve the deduplication gain and at the same time minimize the privacy leakage. Our analytical results confirm privacy guarantee and results show that both deduplication benefit and privacy of RARE can be preserved.
引用
收藏
页码:444 / 449
页数:6
相关论文
共 50 条
  • [1] Side Channels in Cloud Services Deduplication in Cloud Storage
    Harnik, Danny
    Pinkas, Benny
    Shulman-Peleg, Alexandra
    [J]. IEEE SECURITY & PRIVACY, 2010, 8 (06) : 40 - 47
  • [2] Privacy Aware Data Deduplication for Side Channel in Cloud Storage
    Yu, Chia-Mu
    Gochhayat, Sarada Prasad
    Conti, Mauro
    Lu, Chun-Shien
    [J]. IEEE TRANSACTIONS ON CLOUD COMPUTING, 2020, 8 (02) : 597 - 609
  • [3] Comments on "Privacy Aware Data Deduplication for Side Channel in Cloud Storage"
    Tang, Xin
    Zhu, Yudan
    Fu, Mingjun
    [J]. IEEE TRANSACTIONS ON CLOUD COMPUTING, 2024, 12 (02) : 814 - 817
  • [4] Client-Side Deduplication for Protection of a Private Data in Cloud Storage
    Kim, Won-Bin
    Lee, Im Yeong
    [J]. ADVANCED SCIENCE LETTERS, 2016, 22 (09) : 2448 - 2452
  • [5] Dynamic Data Deduplication in Cloud Storage
    Leesakul, Waraporn
    Townend, Paul
    Xu, Jie
    [J]. 2014 IEEE 8TH INTERNATIONAL SYMPOSIUM ON SERVICE ORIENTED SYSTEM ENGINEERING (SOSE), 2014, : 320 - 325
  • [6] Public Auditing for Encrypted Data with Client-Side Deduplication in Cloud Storage
    HE Kai
    HUANG Chuanhe
    ZHOU Hao
    SHI Jiaoli
    WANG Xiaomao
    DAN Feng
    [J]. Wuhan University Journal of Natural Sciences, 2015, 20 (04) : 291 - 298
  • [7] Encrypted Data Deduplication in Cloud Storage
    Fan, Chun-I
    Huang, Shi-Yuan
    Hsu, Wen-Che
    [J]. 2015 10TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS), 2015, : 18 - 25
  • [8] Data Deduplication Technology for Cloud Storage
    He, Qinlu
    Bian, Genqing
    Shao, Bilin
    Zhang, Weiqi
    [J]. TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2020, 27 (05): : 1444 - 1451
  • [9] Deduplication Based Storage and Retrieval of Data from Cloud Environment
    Pritha, N. Lakshmi
    Velmurugan, N.
    Winster, S. Godfrey
    Vijayaraj, A.
    [J]. INTERNATIONAL CONFERENCE ON INNOVATION INFORMATION IN COMPUTING TECHNOLOGIES, 2015, 2015,
  • [10] Differentially private client-side data deduplication protocol for cloud storage services
    Shin, Youngjoo
    Kim, Kwangjo
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (12) : 2114 - 2123