Secure Cloud Storage with Client-side Encryption using a Trusted Execution Environment

被引:3
|
作者
da Rocha, Marciano [1 ]
Gomes Valadares, Dalton Cezane [2 ]
Perkusich, Angelo [3 ]
Gorgonio, Kyller Costa [4 ]
Pagno, Rodrigo Tomaz [1 ]
Will, Newton Carlos [1 ]
机构
[1] Fed Univ Technol, Dept Comp Sci, Dois Vizinhos, Parana, Brazil
[2] Fed Inst Pernambuco, Dept Mech Engn, Caruaru, Brazil
[3] Univ Fed Campina Grande, Dept Elect Engn, Campina Grande, Paraiba, Brazil
[4] Univ Fed Campina Grande, Dept Comp Sci, Campina Grande, Paraiba, Brazil
关键词
Intel SGX; Data Sealing; File Encryption; Confidentiality; Integrity; Secure Storage; Cloud Storage;
D O I
10.5220/0009130600310043
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the evolution of computer systems, the amount of sensitive data to be stored as well as the number of threats on these data grow up, making the data confidentiality increasingly important to computer users. Currently, with devices always connected to the Internet, the use of cloud data storage services has become practical and common, allowing quick access to such data wherever the user is. Such practicality brings with it a concern, precisely the confidentiality of the data which is delivered to third parties for storage. In the home environment, disk encryption tools have gained special attention from users, being used on personal computers and also having native options in some smartphone operating systems. The present work uses the data sealing, feature provided by the Intel Software Guard Extensions (Intel SGX) technology, for file encryption. A virtual file system is created in which applications can store their data, keeping the security guarantees provided by the Intel SGX technology, before send the data to a storage provider. This way, even if the storage provider is compromised, the data are safe. To validate the proposal, the Cryptomator software, which is a free client-side encryption tool for cloud files, was integrated with an Intel SGX application (enclave) for data sealing. The results demonstrate that the solution is feasible, in terms of performance and security, and can be expanded and refined for practical use and integration with cloud synchronization services.
引用
收藏
页码:31 / 43
页数:13
相关论文
共 50 条
  • [1] Secure Client-Side Deduplication Scheme for Cloud with Dual Trusted Execution Environment
    Verma, Garima
    [J]. IETE JOURNAL OF RESEARCH, 2023, 69 (10) : 7015 - 7025
  • [2] ENDBOX: Scalable Middlebox Functions Using Client-Side Trusted Execution
    Goltzsche, David
    Ruesch, Signe
    Nieke, Manuel
    Vaucher, Sebastien
    Weichbrodt, Nico
    Schiavoni, Valerio
    Aublin, Pierre-Louis
    Costa, Paolo
    Fetzer, Christof
    Felber, Pascal
    Pietzuch, Peter
    Kapitza, Ruediger
    [J]. 2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2018, : 386 - 397
  • [3] Delta Encoding Overhead Analysis of Cloud Storage Systems using Client-side Encryption
    Henziger, Eric
    Carlsson, Niklas
    [J]. 11TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2019), 2019, : 183 - 190
  • [4] Client-Side Encryption in Cloud Storage Using Lagrange Interpolation and Pairing Based Cryptography
    Ranjani, R. Siva
    Bhaskari, D. Lalitha
    Avadhani, P. S.
    [J]. ICT AND CRITICAL INFRASTRUCTURE: PROCEEDINGS OF THE 48TH ANNUAL CONVENTION OF COMPUTER SOCIETY OF INDIA - VOL I, 2014, 248 : 473 - 480
  • [5] SecReS: A Secure and Reliable Storage Scheme for Cloud with Client-side Data Deduplication
    Islam, Tariqul
    Mistareehi, Hassan
    Manivannan, D.
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [6] Secure and efficient client-side data deduplication with public auditing in cloud storage
    Dang, Qianlong
    Ma, Hua
    Liu, Zhenhua
    Xie, Ying
    [J]. International Journal of Network Security, 2020, 22 (03) : 462 - 475
  • [7] Toward Practical Client-Side Encryption in Cloud Computing
    Deng, Robert
    [J]. PROCEEDINGS OF THE 19TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ACM ASIACCS 2024, 2024, : 1 - 1
  • [8] SaveMe: Client-Side Aggregation of Cloud Storage
    Song, Gyuwon
    Kim, Suhyun
    Seo, Dongmahn
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2015, 61 (03) : 302 - 310
  • [9] Client-side encryption for privacy-sensitive applications on the cloud
    Souza, Stefano M. P. C.
    Puttini, Ricardo S.
    [J]. 2ND INTERNATIONAL CONFERENCE ON CLOUD FORWARD: FROM DISTRIBUTED TO COMPLETE COMPUTING, 2016, 97 : 126 - 130
  • [10] Blockchain-based secure deduplication of encrypted data supporting client-side semantically secure encryption without trusted third party
    Qin, Guiyun
    Li, Limin
    Liu, Pengtao
    Hu, Chengyu
    Guo, Shanqing
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2024, 35 (04)