End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem
Jonas Hofmann, Kien Tuong Truong
摘要
End-to-end encrypted cloud storage offers a way for individuals and organisations to delegate their storage needs to a third-party, while keeping control of their data using cryptographic techniques. We conduct a cryptographic analysis of various products in the ecosystem, showing that many providers fail to provide an adequate level of security. In particular, we provide an in-depth analysis of five end-to-end encrypted cloud storage systems, namely Sync, pCloud, Icedrive, Seafile, and Tresorit, in the setting of a malicious server. These companies cumulatively have over 22 million users and are major providers in the field. We unveil severe cryptographic vulnerabilities in four of them. Our attacks invalidate the marketing claims made by the providers of these systems, showing that a malicious server can, in some cases, inject files in the encrypted storage of users, tamper with file data, and even gain direct access to the content of the files. Many of our attacks affect multiple providers in the same way, revealing common failure patterns in independent cryptographic designs. We conclude by discussing the significance of these patterns beyond the security of the specific providers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 被引用 1 次
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
它引用的顶会 Paper8
- Verena: End-to-End Integrity Protection for Web ApplicationsNikolaos Karapanos, Alexandros Filios, Raluca Ada Popa, Srdjan CapkunS&P 2016 · 被引用 59 次
- A Formal Treatment of End-to-End Encrypted Cloud StorageMatilda Backendal, Hannah Davis, Felix Günther, Miro Haller 等CRYPTO 2024 · 被引用 15 次
- Caveat Implementor! Key Recovery Attacks on MEGAMartin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. PatersonEUROCRYPT 2023 · 被引用 8 次
- Victory by KO: Attacking OpenPGP Using Key OverwritingLara Bruseghini, Daniel Huigens, Kenneth G. PatersonCCS 2022 · 被引用 6 次
- Metal: A Metadata-Hiding File-Sharing SystemWeikeng Chen, Raluca Ada PopaNDSS 2020
相关 Paper
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
- DORY: An Encrypted Search System with Distributed TrustEmma Dauterman, Eric Feng, Ellen Luo, Raluca Ada Popa 等OSDI 2020 · 被引用 77 次
- Searching Encrypted Data with Size-Locked IndexesMin Xu, Armin Namavari, David Cash, Thomas RistenpartUSENIX Security 2021 · 被引用 10 次
- Secure Cloud Storage: Modularization, Network Adversaries and Adaptive CorruptionsJonas Janneck, Doreen RiepelEUROCRYPT 2026
- ObliviSync: Practical Oblivious File Backup and SynchronizationAdam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. RocheNDSS 2017 · 被引用 13 次
