End-to-Same-End Encryption: Modularly Augmenting an App with an Efficient, Portable, and Blind Cloud Storage
Long Chen, Ya-Nan Li, Qiang Tang, Moti Yung
摘要
The cloud has become pervasive, and we ask: how can we protect cloud data against the cloud itself? For messaging Apps, facilitating user-to-user private communication via a cloud server, security has been formulated and solved efficiently via End-to-End encryption, building on existing channels between end users via servers (i.e., exploiting TLS, and encryption, without the need to program new primitives). However, the analogous problem for Apps employing servers for storing and retrieving end-user data privately, solving the analogous "privacy from the server itself" (cloud-blind storage) where (1) based on existing infrastructure and (2) allowing user mobility, is, in fact, still open. Existing proposals, like password protected secret sharing (PPSS), target end-to-sameend encryption of storage, but need new protocols, whereas most popular commercial cloud storage services are not programmable. Namely they lack the simplicity needed for being portable over any cloud storage service.
Here, we propose a novel system for storing private data in the cloud with the help of a key server (necessary given the requirements). In our system, the user data will be secure from any of: the cloud server, the key server, or any illegitimate users, while the authenticated user can access the data on any devices just via a correct passphrase. The most attractive feature of our system is that it does not require the cloud storage server to support any newly programmable operations, except the existing client login and the data storing. Moreover, our system is simply built on top of the existing App login, and the user only needs one passphrase to login the App and access his secure storage. The security of our protocol, in turn, is proved under our rigorous models, and the efficiency is further demonstrated by real-world network experiments over Amazon S3. We remark that a preliminary variant, based on our principles, was deployed by Snapchat in their My Eyes Only module, serving hundreds of millions of users! PPSS
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman 等OSDI 2024 · 被引用 19 次
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 被引用 1 次
它引用的顶会 Paper8
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
- The Guard's Dilemma: Efficient Code-Reuse Attacks Against Intel SGXAndrea Biondo, Mauro Conti, Lucas Davi, Tommaso Frassetto 等USENIX Security 2018 · 被引用 126 次
- Updatable Oblivious Key Management for Storage SystemsStanislaw Jarecki, Hugo Krawczyk, Jason K. ReschCCS 2019 · 被引用 52 次
- Phoenix: Rebirth of a Cryptographic Password-Hardening ServiceRussell W. F. Lai, Christoph Egger, Dominique Schröder, Sherman S. M. ChowUSENIX Security 2017 · 被引用 45 次
相关 Paper
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 被引用 2 次
- Password-Protected Key Retrieval with(out) HSM ProtectionSebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth 等CCS 2024 · 被引用 3 次
- ObliviSync: Practical Oblivious File Backup and SynchronizationAdam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. RocheNDSS 2017 · 被引用 13 次
- CHORUS: Secret Recovery with Ephemeral Client CommitteesDeevashwer Rathee, Emma Dauterman, Allison Li, Raluca Ada PopaS&P 2026 · 被引用 1 次
- SpeechGuard: Recoverable and Customizable Speech Privacy ProtectionJingmiao Zhang, Suyuan Liu, Jiahui Hou, Zhiqiang Wang 等USENIX Security 2025
