MEGA: Malleable Encryption Goes Awry

MEGA: Malleable Encryption Goes Awry
复制标题

MEGA:可塑性加密出了问题

DOI:
--
复制
发表时间:
2023
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Kenneth G. Paterson
Kenneth G. Paterson
中科院分区:
--
文献类型:
--
作者:
Matilda Backendal;Miro Haller;Kenneth G. Paterson

文献摘要

参考文献

被引文献

相似文献

MEGA 是领先的云存储平台,拥有超过 2.5 亿用户和 1000 PB 的存储数据。 MEGA 声称提供用户控制的端到端安全性。这是通过在 MEGA 客户端上完成所有数据加密和解密操作并在仅这些客户端可用的密钥控制下实现的。这样做的目的是保护 MEGA 用户免受 MEGA 本身或控制 MEGA 基础设施的对手的攻击。我们对 MEGA 在此类恶意服务器设置中使用加密技术进行了详细分析。我们提出了针对 MEGA 的五种不同的攻击,这些攻击共同导致用户文件的机密性受到完全损害。此外,用户数据的完整性被破坏到攻击者可以插入他们选择的通过客户端所有真实性检查的恶意文件的程度。我们构建了所有攻击的概念验证版本。五次攻击中有四次非常实用。它们都已负责任地向 MEGA 披露,并且修复工作正在进行中。总而言之,我们的攻击凸显了 MEGA 加密架构中的重大缺陷。我们提出可立即部署的对策以及长期建议。我们还对强威胁模型下大规模加密部署的挑战进行了更广泛的讨论。
MEGA is a leading cloud storage platform with more than 250 million users and 1000 Petabytes of stored data. MEGA claims to offer user-controlled, end-to-end security. This is achieved by having all data encryption and decryption operations done on MEGA clients, under the control of keys that are only available to those clients. This is intended to protect MEGA users from attacks by MEGA itself, or by adversaries who have taken control of MEGA’s infrastructure.We provide a detailed analysis of MEGA’s use of cryptography in such a malicious server setting. We present five distinct attacks against MEGA, which together allow for a full compromise of the confidentiality of user files. Additionally, the integrity of user data is damaged to the extent that an attacker can insert malicious files of their choice which pass all authenticity checks of the client. We built proof-of-concept versions of all the attacks. Four of the five attacks are eminently practical. They have all been responsibly disclosed to MEGA and remediation is underway.Taken together, our attacks highlight significant shortcomings in MEGA’s cryptographic architecture. We present immediately deployable countermeasures, as well as longer-term recommendations. We also provide a broader discussion of the challenges of cryptographic deployment at massive scale under strong threat models.
DOI: 10.14722/ndss.2022.24161
发表时间: 2022
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Weikeng Chen;Thang Hoang;J. Guajardo;A. Yavuz
通讯作者: Weikeng Chen;Thang Hoang;J. Guajardo;A. Yavuz
分区 Oracle 攻击
DOI: --
发表时间: 2021
期刊: USENIX Security Symposium
影响因子: --
作者:
Len, Julia;Grubbs, Paul;Ristenpart, Thomas
通讯作者: Ristenpart, Thomas
快速邮件邮资盖印:从隐形蝾螈到加密
DOI: --
发表时间: 2018
期刊: Advances in Cryptology - CRYPTO
影响因子: --
作者:
Dodis, Yevgeniy;Grubbs, Paul;Ristenpart, Thomas;Woodage, Joanne
通讯作者: Woodage, Joanne