In this paper, we introduce PASSAT, a practical system to boost the security assurance delivered by the current cloud architecture without requiring any changes or cooperation from the cloud service providers. PASSAT is an application transparent to the cloud servers that allows users to securely and efficiently store and access their files stored on public cloud storage based on a single master password. Using a fast and light-weight XOR secret sharing scheme, PASSAT secret-shares users' files and distributes them among n publicly available cloud platforms. To access the files, PASSAT communicates with any k out of n cloud platforms to receive the shares and runs a secret-sharing reconstruction algorithm to recover the files. An attacker (insider or outsider) who compromises or colludes with less than k platforms cannot learn the user's files or modify the files stealthily. To authenticate the user to multiple cloud platforms, PASSAT crucially stores the authentication credentials, specific to each platform on a password manager, protected under the user's master password. Upon requesting access to files, the user enters the password to unlock the vault and fetches the authentication tokens using which PASSAT can interact with cloud storage. Our instantiation of PASSAT based on (2, 3)-XOR secret sharing of Kurihara et al., implemented with three popular storage providers, namely, Google Drive, Box, and Dropbox, confirms that our approach can efficiently enhance the confidentiality, integrity, and availability of the stored files with no changes on the servers.
在本文中,我们介绍了Passat,这是一个实用的系统,旨在提高当前云体系结构提供的安全保证,而无需云服务提供商进行任何更改或合作。 Passat是针对云服务器的应用程序,它允许用户根据单个主密码安全有效地存储和访问其存储在公共云存储上的文件。使用快速且轻巧的XOR秘密共享方案,Passat Secret-Shectres用户的文件并将其分配在n个公开可用的云平台中。要访问文件,Passat与N云平台的任何K通信以接收股票并运行秘密共享重建算法以恢复文件。妥协或碰撞K平台的攻击者(内部或局外人)无法学习用户的文件或偷偷地修改文件。为了将用户身份验证到多个云平台,Passat至关重要的是存储身份验证凭据,该验证凭证在密码管理器上,在用户主密码受到保护的密码管理器上。在请求访问文件后,用户输入密码以解锁保险库,并使用Passat可以与Cloud Storage进行交互的身份验证令牌。我们基于(2,3)-XOR秘密共享Kurihara等人对Passat的实例化,该共享与三个受欢迎的存储提供商(即Google Drive,Box和Dropbox)实施,确认我们的方法可以有效地增强机密性,完整性,完整性,并且在服务器上无需更改的存储文件。