TY - GEN
T1 - Revisiting Shared Data Protection against Key Exposure
AU - Kapusta, Katarzyna
AU - Rambaud, Matthieu
AU - Memmi, Gerard
N1 - Publisher Copyright:
© 2020 ACM.
PY - 2020/10/5
Y1 - 2020/10/5
N2 - This paper puts a new light on computational secret sharing with a view towards distributed storage environments. It starts with revisiting the security model for encrypted data protection against key exposure. The goal of this revisiting is to take advantage of the characteristics of distributed storage in order to design faster key leakage resisting schemes, with the same security properties as the existing ones in this context of distributed storage. We then introduce two novel schemes that match our - -all storage places or nothing - - security level of secret sharing under key exposure. The first one is based on standard block cipher encryption. The second one fits both in the random oracle model (e.g. Keccak) or in the idealized blockcipher model with twice larger key than the security parameter (e.g. an idealized AES256 would achieve 128 bits security). The first one reduces by half the amount of the processing required to be done in addition to data encryption with regard to the fastest state-of-the-art solution, whereas the second one completely eradicates additional processing. We confirm the complexity results by presenting a performance evaluation. A non-negligible part of our contribution lies in the provided security analysis. In addition to giving security proofs for our schemes, we revisit the ones of previous work and point out structural weaknesses in a context of key exposure.
AB - This paper puts a new light on computational secret sharing with a view towards distributed storage environments. It starts with revisiting the security model for encrypted data protection against key exposure. The goal of this revisiting is to take advantage of the characteristics of distributed storage in order to design faster key leakage resisting schemes, with the same security properties as the existing ones in this context of distributed storage. We then introduce two novel schemes that match our - -all storage places or nothing - - security level of secret sharing under key exposure. The first one is based on standard block cipher encryption. The second one fits both in the random oracle model (e.g. Keccak) or in the idealized blockcipher model with twice larger key than the security parameter (e.g. an idealized AES256 would achieve 128 bits security). The first one reduces by half the amount of the processing required to be done in addition to data encryption with regard to the fastest state-of-the-art solution, whereas the second one completely eradicates additional processing. We confirm the complexity results by presenting a performance evaluation. A non-negligible part of our contribution lies in the provided security analysis. In addition to giving security proofs for our schemes, we revisit the ones of previous work and point out structural weaknesses in a context of key exposure.
KW - all-or-nothing
KW - cloud storage security
KW - computational secret sharing
KW - confidentiality under key exposure
KW - data protection
KW - distributed storage security
U2 - 10.1145/3320269.3372198
DO - 10.1145/3320269.3372198
M3 - Conference contribution
AN - SCOPUS:85096388231
T3 - Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2020
SP - 165
EP - 177
BT - Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2020
PB - Association for Computing Machinery, Inc
T2 - 15th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2020
Y2 - 5 October 2020 through 9 October 2020
ER -