首页> 外文会议>Symposium on Mass Storage Systems and Technologies >SecDep: A user-aware efficient fine-grained secure deduplication scheme with multi-level key management
【24h】

SecDep: A user-aware efficient fine-grained secure deduplication scheme with multi-level key management

机译:SECDEP:具有多级密钥管理的用户意识到高效的细粒度安全重复数据删除方案

获取原文

摘要

Nowadays, many customers and enterprises backup their data to cloud storage that performs deduplication to save storage space and network bandwidth. Hence, how to perform secure deduplication becomes a critical challenge for cloud storage. According to our analysis, the state-of-the-art secure deduplication methods are not suitable for cross-user finegrained data deduplication. They either suffer brute-force attacks that can recover files falling into a known set, or incur large computation (time) overheads. Moreover, existing approaches of convergent key management incur large space overheads because of the huge number of chunks shared among users. Our observation that cross-user redundant data are mainly from the duplicate files, motivates us to propose an efficient secure deduplication scheme SecDep. SecDep employs User-Aware Convergent Encryption (UACE) and Multi-Level Key management (MLK) approaches. (1) UACE combines cross-user file-level and inside-user chunk-level deduplication, and exploits different secure policies among and inside users to minimize the computation overheads. Specifically, both of file-level and chunk-level deduplication use variants of Convergent Encryption (CE) to resist brute-force attacks. The major difference is that the file-level CE keys are generated by using a server-aided method to ensure security of cross-user deduplication, while the chunk-level keys are generated by using a user-aided method with lower computation overheads. (2) To reduce key space overheads, MLK uses file-level key to encrypt chunk-level keys so that the key space will not increase with the number of sharing users. Furthermore, MLK splits the file-level keys into share-level keys and distributes them to multiple key servers to ensure security and reliability of file-level keys. Our security analysis demonstrates that SecDep ensures data confidentiality and key security. Our experiment results based on several large real-world datasets show that SecDep is mor- time-efficient and key-space-efficient than the state-of-the-art secure deduplication approaches.
机译:如今,许多客户和企业将其数据备份到云存储,执行重复数据删除以保存存储空间和网络带宽。因此,如何执行安全的重复数据删除成为云存储的一个关键挑战。根据我们的分析,最先进的安全重复数据删除方法不适合交叉用户FineGreated数据重复数据删除。它们要么遭受丢弃的强力攻击,可以将文件恢复到已知的集合中,或产生大计算(时间)开销。此外,由于用户共享的大量块,现有的会聚密钥管理方法会产生大的空间开销。我们观察到跨用户冗余数据主要来自重复文件,激励我们提出了一种高效的安全重复数据删除方案SECDEP。 Secdep采用用户感知收敛加密(UACE)和多级密钥管理(MLK)方法。 (1)UACE结合了跨用户文件级和内部用户块级重复数据删除,并利用用户之间的不同安全策略,以最小化计算开销。具体而言,文件级和块级重复数据删除的两个都使用会聚加密(CE)的变体来抵抗蛮力攻击。主要区别在于,通过使用服务器辅助方法来生成文件级CE键,以确保交叉用户重复数据删除的安全性,而通过使用具有较低计算开销的用户辅助方法生成块级键。 (2)为了减少关键空间开销,MLK使用文件级键加密块级键,使得关键空间不会随着共享用户的数量而增加。此外,MLK拆分文件级的密钥为共享级密钥,并将其分发到多个关键服务器,以确保文件级密钥的安全性和可靠性。我们的安全分析表明SECDEP确保数据机密性和关键安全性。我们的实验结果基于几个大型现实世界数据集,表明SECDEP是Mor-you的效率和关键空间效率,而不是最先进的安全重复数据删除方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号