NewMCOS: Towards a Practical Multi-Cloud Oblivious Storage Scheme

被引:33
|
作者
Liu, Zheli [1 ,2 ]
Li, Bo [1 ,2 ]
Huang, Yanyu [1 ,2 ]
Li, Jin [3 ]
Xiang, Yang [4 ]
Pedrycz, Witold [5 ]
机构
[1] Nankai Univ, Coll Cyber Sci, Tianjin 300071, Peoples R China
[2] Nankai Univ, Coll Comp Sci, Tianjin 300071, Peoples R China
[3] Guangzhou Univ, Sch Comp Sci, Guangzhou 51006, Guangdong, Peoples R China
[4] Swinburne Univ Technol, Sch Software & Elect Engn, Hawthorn, Vic, Australia
[5] Univ Alberta, Dept Elect & Comp Engn, Edmonton, AB T6G 2R3, Canada
基金
中国国家自然科学基金;
关键词
Data privacy; oblivious RAM; cloud storage; access pattern;
D O I
10.1109/TKDE.2019.2891581
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Encryption alone is not enough to protect data privacy, because access pattern leaks some sensitive information. Oblivious RAM (ORAM), the solution to this problem, is still far from practical deployment for heavy storage and communication/ computation overhead. To reduce them, an insightful idea was proposed to utilize non-colluding clouds to shift client computation and client-cloud communication to the clouds. The proposed multi-cloud ORAM achieved $O$O(1) client-cloud bandwidth cost and removed most of client computation. In this paper, we exploit "disconnected ORAM operation" and design "two-layer encryption" to further reduce these overheads. Experiments show that our proposed scheme, NewMCOS, significantly reduces evict cache size from GB/MB to KB level with about 2-3 times lower response time and 20 percent savings in bandwidth for clouds, compared to other schemes. Theoretically speaking, we reduce evict cache size from $O(\sqrt{N})$O(N) to $O(ZK)$O(ZK), where $N$N is the number of real data blocks, $K$K is the number of clouds ($2<K << \sqrt{N}$2<K<<N), and $Z$Z is the number of real blocks uploaded from the client for eviction. By employing "lazy eviction operation", the write frequency is reduced by $O(Z)$O(Z), the shuffling bandwidth cost is reduced by $\Omega (Z\; \log Z)$omega(ZlogZ). Meanwhile, NewMCOS is proved to be secure.
引用
收藏
页码:714 / 727
页数:14
相关论文
共 50 条
  • [41] Secure Cloud Storage: A framework for Data Protection as a Service in the multi-cloud environment
    Quang Hieu Vu
    Colombo, Maurizio
    Asal, Rasool
    Sajjad, Ali
    El-Moussa, Fadi Ali
    Dimitrakos, Theo
    [J]. 2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 638 - 642
  • [42] A Multi-Cloud Approach for Secure Data Storage on Smart Device
    Alqahtani, Hassan Saad
    Sant, Paul
    [J]. 2016 SIXTH INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION AND COMMUNICATION TECHNOLOGY AND ITS APPLICATIONS (DICTAP), 2016, : 63 - 69
  • [43] Practical Oblivious Outsourced Storage
    Williams, Peter
    Sion, Radu
    Sotakova, Miroslava
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2011, 14 (02)
  • [44] A Web Client Secure Storage Approach in Multi-Cloud Environment
    Bin Sahbudin, Murtadha Arif
    Di Pietro, Riccardo
    Scarpa, Marco
    [J]. 2019 4TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND SECURITY (ICCCS), 2019,
  • [45] A Brokerage Approach for Secure Multi-Cloud Storage Resource Management
    Sukmana, Muhammad Ihsan Haikal
    Torkura, Kennedy Aondona
    Prasetyo, Sezi Dwi Sagarianti
    Cheng, Feng
    Meinel, Christoph
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT II, 2020, 336 : 102 - 119
  • [46] Efficient Low-cost Storage Strategy in Multi-Cloud
    Yuan Naiheng
    Guo Yijun
    Hao Jianjun
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2712 - 2716
  • [47] TrustyDrive, a Multi-Cloud Storage Service that Protects Your Privacy
    Pottier, Remy
    Menaud, Jean-Marc
    [J]. PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 937 - 940
  • [48] Towards Interpreting Models to Orchestrate IaaS Multi-Cloud Infrastructures
    Allison, Mark
    Turner, Stephen
    Allen, Andrew A.
    [J]. 10TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION (ICCSE 2015), 2015, : 80 - 85
  • [49] Towards a distributed SaaS management system in a multi-cloud environment
    Linda Ouchaou
    Hassina Nacer
    Chahrazed Labba
    [J]. Cluster Computing, 2022, 25 : 4051 - 4071
  • [50] Towards Quality Guided Data Integration on Multi-cloud Settings
    Carvalho, Daniel A. S.
    [J]. SERVICE-ORIENTED COMPUTING - ICSOC 2016 WORKSHOPS, 2017, 10380 : 139 - 144