A Formal Treatment of End-to-End Encrypted Cloud Storage
Matilda Backendal, Hannah Davis, Felix Günther, Miro Haller, Kenneth G. Paterson
Abstract
Users increasingly store their data in the cloud, thereby benefiting from easy access, sharing, and redundancy. To additionally guarantee security of the outsourced data even against a server compromise, some service providers have started to offer end-to-end encrypted (E2EE) cloud storage. With this cryptographic protection, only legitimate owners can read or modify the data. However, recent attacks on the largest E2EE providers have highlighted the lack of solid foundations for this emerging type of service.
In this paper, we address this shortcoming by initiating the formal study of E2EE cloud storage. We give a formal syntax to capture the core functionality of a cloud storage system, capturing the real-world complexity of such a system's constituent interactive protocols. We then define game-based security notions for confidentiality and integrity of a cloud storage system against a fully malicious server. We treat both selective and fully adaptive client compromises. Our notions are informed by recent attacks on E2EE cloud storage providers. In particular we show that our syntax is rich enough to capture the core functionality of MEGA and that recent attacks on it arise as violations of our security notions. Finally, we present an E2EE cloud storage system that provides all core functionalities and that is both efficient and provably secure with respect to our selective security notions. Along the way, we discuss challenges on the path towards bringing the security of cloud storage up to par with other end-to-end primitives, such as secure messaging and TLS.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get fa4f2804-29a6-457b-8d6a-d146b2969338Cited by top-tier papers6
- End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemJonas Hofmann, Kien Tuong TruongCCS 2024 · 5 citations
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 1 citation
- The SecureDrop Protocol: End-to-End Encrypted Whistleblowing for AllGiulio Berra, Felix Linker, Luca Maier, Cory Francis Myers et al.CCS 2026
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key ReconstructionAlexandra Boldyreva, Deep Inder Mohan, Tianxin TangCCS 2025
Related papers
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
- Secure Cloud Storage: Modularization, Network Adversaries and Adaptive CorruptionsJonas Janneck, Doreen RiepelEUROCRYPT 2026
- Caveat Implementor! Key Recovery Attacks on MEGAMartin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. PatersonEUROCRYPT 2023 · 8 citations
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
- End-to-Same-End Encryption: Modularly Augmenting an App with an Efficient, Portable, and Blind Cloud StorageLong Chen, Ya-Nan Li, Qiang Tang, Moti YungUSENIX Security 2022
