Updatable Oblivious Key Management for Storage Systems

Updatable Oblivious Key Management for Storage Systems
复制标题

DOI:
10.1145/3319535.3363196
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Stanislaw Jarecki;H. Krawczyk;Jason K. Resch
Stanislaw Jarecki;H. Krawczyk;Jason K. Resch
中科院分区:
其他
文献类型:
--
作者:
Stanislaw Jarecki;H. Krawczyk;Jason K. Resch

文献摘要

被引文献

相似文献

我们将遗忘的密钥管理系统(KMS)作为传统基于包装的KMS的更安全替代方案,该kms构成了大规模数据存储部署中密钥管理的骨干。新系统以遗忘的伪随机函数(OPRF)为基础,隐藏了KMS中的键和对象标识符,为密钥传输提供无条件的安全性,提供钥匙可验证性,减少存储等等。此外,我们展示了如何在分布式阈值实现中提供所有这些功能,以增强对服务器折衷的保护。我们使用可更新的加密功能扩展了该系统,该功能支持密钥更新(称为密钥旋转),以便在KMS服务器周期性更改OPRF键时,一个非常有效的更新过程允许KMS服务的客户端非连续性地更新所有它的加密数据只能由新密钥解密。这可以通过向前和副业后的安全性增强安全性,即分别针对公共持有的客户的OPRF密钥来抵御未来和过去的妥协。此外,与传统KMS相反,我们的解决方案支持公共密钥加密并分配与KMS进行数据加密的任何互动(仅由客户解密需要此类通信)。我们的解决方案基于最新的可更新加密工作,但可用于远程KMS设置的大量增强功能。除了进行关键的安全性改进外,我们的设计还高效,可以在实践中使用。我们报告实验实施和绩效。
We introduce Oblivious Key Management Systems (KMS) as a much more secure alternative to traditional wrapping-based KMS that form the backbone of key management in large-scale data storage deployments. The new system, that builds on Oblivious Pseudorandom Functions (OPRF), hides keys and object identifiers from the KMS, offers unconditional security for key transport, provides key verifiability, reduces storage, and more. Further, we show how to provide all these features in a distributed threshold implementation that enhances protection against server compromise. We extend this system with updatable encryption capability that supports key updates (known as key rotation) so that upon the periodic change of OPRF keys by the KMS server, a very efficient update procedure allows a client of the KMS service to non-interactively update all its encrypted data to be decryptable only by the new key. This enhances security with forward and post-compromise security, namely, security against future and past compromises, respectively, of the client's OPRF keys held by the KMS. Additionally, and in contrast to traditional KMS, our solution supports public key encryption and dispenses with any interaction with the KMS for data encryption (only decryption by the client requires such communication). Our solutions build on recent work on updatable encryption but with significant enhancements applicable to the remote KMS setting. In addition to the critical security improvements, our designs are highly efficient and ready for use in practice. We report on experimental implementation and performance.