Secure Overlay Cloud Storage with Access Control and Assured Deletion
摘要We can now outsource data backups off-site to third-party cloud storage services so as to reduce data management costs. However, we must provide security guarantees for the outsourced data, which is now maintained by third parties. We design and implement FADE, a secure overlay cloud storage system that achieves fine-grained, policy-based access control and file assured deletion. It associates outsourced files with file access policies, and assuredly deletes files to make them unrecoverable to anyone upon revocations of file access policies. To achieve such security goals, FADE is built upon a set of cryptographic key operations that are self-maintained by a quorum of key managers that are independent of third-party clouds. In particular, FADE acts as an overlay system that works seamlessly atop today's cloud storage services. We implement a proof-of-concept prototype of FADE atop Amazon S3, one of today's cloud storage services. We conduct extensive empirical studies, and demonstrate that FADE provides security protection for outsourced data, while introducing only minimal performance and monetary cost overhead. Our work provides insights of how to incorporate value-added security features into today's cloud storage services.
著者Tang Y, Lee PPC, Lui JCS, Perlman R
期刊名稱IEEE Transactions on Dependable and Secure Computing
IEEE Transactions on Dependable and Secure Computing is considered a top-tier journal by the external visiting committee in the Faculty of Enginee
出版社Institute of Electrical and Electronics Engineers (IEEE)
頁次903 - 916
關鍵詞Access control; assured deletion; backup/recovery; cloud storage
Web of Science 學科類別Computer Science; Computer Science, Hardware & Architecture; COMPUTER SCIENCE, HARDWARE & ARCHITECTURE; Computer Science, Information Systems; COMPUTER SCIENCE, INFORMATION SYSTEMS; Computer Science, Software Engineering; COMPUTER SCIENCE, SOFTWARE ENGINEERING

