secure cloud storage meets with secure network coding fei chen (chinese university of hong kong,...

25
Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan Yang (Stony Brook University, USA) Sherman S. M. Chow (Chinese University of Hong Kong, Hong Kong)

Upload: benjamin-antcliff

Post on 02-Apr-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Secure Cloud Storagemeets with

Secure Network Coding

Fei Chen (Chinese University of Hong Kong, Hong Kong)

Tao Xiang (Chongqing University, China)

Yuanyuan Yang (Stony Brook University, USA)

Sherman S. M. Chow (Chinese University of Hong Kong, Hong Kong)

Page 2: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Roadmap• Preliminaries• Generic Construction

• Technical Obstacles

• Showcase: A Novel Protocol• Extensions

• Third-party Auditing• User Anonymity

• Summary

Page 3: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Secure Cloud Storage (SCS)

• Juels-Kaliski, Ateniese et al. (both CCS’07)• Wang, Chow, Wang, Ren, Lou (IEEE TC’13)• Yang-Jia (TPDS’13)• Wang, Chow, Li, Li (ICDCS’13)

Page 4: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

SCS Protocol

User

Cloud

Page 5: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Handling Security

Page 6: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

User

Cloud

Page 7: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Security Definition

Page 8: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Secure Network Coding (SNC)

• Ahlswede, Cai, Li, Yeung from CUHK (IEEE TIT’00)• Li, Yeung, Cai (IEEE TIT’03); Cai-Yeung (ISIT’02)• Gkantsidis-Rodriguez (INFOCOM’06); Li, Lui, Chiu (ICNP’06)• Agrawal-Boneh (ACNS’09); Catalano et al. (PKC’12)• (many others)

Page 9: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

SNC Protocol

Page 10: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Security Definition

Page 11: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

OUR WORK

Page 12: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

1. Generic Construction

Page 13: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Basic Idea

Page 14: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan
Page 15: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Optimization

Page 16: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Security

Page 17: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Data Recovery Algorithm

Page 18: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

2. A Novel SCS Protocol• Based on a recent SNC protocol by Catalano et al.

(PKC’12)

• First publicly verifiable secure cloud storage protocol which is provably secure (not random oracle heuristics)

Page 19: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Detailed Construction

Page 20: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Theoretical Performance• Asymptotic performance comparable to previous work

Page 21: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Experimental Performance• Benchmark (data from Wikipedia)

• Storage and communication overhead

Page 22: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Computation Cost• (Time is in milliseconds.)

• The protocol is effective in practice.• Efficiency cost is acceptable for a standard model proof.

• For protocols with security argued with random oracle heuristics, one may instantiate with larger cryptographic groups / security parameters, which results in lower efficiency anyways.

Page 23: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Supporting Third-Party Auditing

• Idea: mask the returned result with randomized vectors with coefficients all 0 (zero-knowledge proof of knowledge)

• [Wang, Chow, Wang, Ren, Lou (IEEE TC’13)]

Page 24: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Supporting User Anonymity

• Idea: randomization again (blind signature approach)• [Wang, Chow, Li, Li (ICDCS’13)]

Page 25: Secure Cloud Storage meets with Secure Network Coding Fei Chen (Chinese University of Hong Kong, Hong Kong) Tao Xiang (Chongqing University, China) Yuanyuan

Summary• Secure Cloud Storage meets with Secure Network Coding

• A generic construction

• A novel SCS protocol

• Security definition and security proof

• Support of third-party auditing and user anonymity