Abstract
Conventional encryption schemes are being used over the years for securing outsourced data to cloud. However, this impedes deduplication-the ability to identify and remove duplicate data from storage server. The idea of Convergent Encryption was introduced to overcome this problem which ensures that identical plaintext files will always produce identical ciphertexts and thus enabling deduplication. Nonetheless, this scheme is vulnerable to a side-channel attack called 'confirmation-of-a-file' and its variant 'learn-the-remaining-information' attack which breach user privacy by observing the deduplication operation. To resolve the above two seemingly contrasting issues, we propose a scheme which blends convergent encryption with a traditional access control scheme for simultaneously achieving confidentiality and deduplication. Both theoretical security analysis and experimental results show that our scheme is semantically secure and resilient against attacks. It incurs minor storage and latency overhead while performing file and block level deduplication. Furthermore, it ensures secure and fine-grained access control of outsourced data by efficiently handling key-management process.
Original language | English |
---|---|
Title of host publication | 2020 IEEE 17th Annual Consumer Communications and Networking Conference, CCNC 2020 |
Pages | 1-6 |
Number of pages | 6 |
ISBN (Electronic) | 9781728138930 |
DOIs | |
State | Published - Jan 2020 |
Event | 17th IEEE Annual Consumer Communications and Networking Conference, CCNC 2020 - Las Vegas, United States Duration: Jan 10 2020 → Jan 13 2020 |
Publication series
Name | 2020 IEEE 17th Annual Consumer Communications and Networking Conference, CCNC 2020 |
---|---|
Volume | 2019-January |
Conference
Conference | 17th IEEE Annual Consumer Communications and Networking Conference, CCNC 2020 |
---|---|
Country/Territory | United States |
City | Las Vegas |
Period | 1/10/20 → 1/13/20 |
Bibliographical note
Publisher Copyright:© 2020 IEEE.
Keywords
- Access Control
- Authentication
- Confidentiality
- Convergent Encryption
- Deduplication
ASJC Scopus subject areas
- Artificial Intelligence
- Computer Networks and Communications
- Hardware and Architecture
- Safety, Risk, Reliability and Quality
- Media Technology
- Communication