This Paper Is Included in the Proceedings of the 11th Usenix Symposium on Networked Systems Design and Implementation (nsdi '14). Building Web Applications on Top of Encrypted Data Using Mylar Building Web Applications on Top of Encrypted Data Using Mylar

This Paper Is Included in the Proceedings of the 11th Usenix Symposium on Networked Systems Design and Implementation (nsdi '14). Building Web Applications on Top of Encrypted Data Using Mylar Building Web Applications on Top of Encrypted Data Using Mylar
复制标题

DOI:
--
复制
发表时间:
--
期刊:
--
影响因子:
--
通讯作者:
Raluca A. Popa;Emily Stark;S. Valdez;Jonas Helfer;Nickolai Zeldovich;H. Balakrishnan
Raluca A. Popa;Emily Stark;S. Valdez;Jonas Helfer;Nickolai Zeldovich;H. Balakrishnan
中科院分区:
其他
文献类型:
--
作者:
Raluca A. Popa;Emily Stark;S. Valdez;Jonas Helfer;Nickolai Zeldovich;H. Balakrishnan

文献摘要

被引文献

相似文献

Web应用程序依赖于服务器来存储和处理机密信息。但是,任何获得服务器访问权限的人(例如,攻击者、好奇的管理员或政府)可以获得存储在那里的所有数据。本文介绍了Mylar,一个用于构建Web应用程序的平台,它可以保护数据机密性,防止攻击者完全访问服务器。Mylar在服务器上存储加密的敏感数据,并仅在用户的浏览器中解密这些数据。聚酯薄膜解决了三个挑战,使这种方法的工作。首先,Mylar允许服务器对加密的文档执行关键字搜索,即使文档是用不同的密钥加密的。其次,Mylar允许用户在存在活跃对手的情况下安全地共享密钥和加密数据。最后,Mylar确保客户端应用程序代码是真实的,即使服务器是恶意的。基于Meteor框架构建的Mylar原型的结果是有希望的:移植6个应用程序平均只需要更改36行代码,并且性能开销适中,相当于17%的吞吐量损失和50 ms的延迟增加,用于在聊天应用程序中发送消息。
Web applications rely on servers to store and process confidential information. However, anyone who gains access to the server (e.g., an attacker, a curious administrator, or a government) can obtain all of the data stored there. This paper presents Mylar, a platform for building web applications , which protects data confidentiality against attackers with full access to servers. Mylar stores sensitive data encrypted on the server, and decrypts that data only in users' browsers. Mylar addresses three challenges in making this approach work. First, Mylar allows the server to perform keyword search over encrypted documents, even if the documents are encrypted with different keys. Second, Mylar allows users to share keys and encrypted data securely in the presence of an active adversary. Finally , Mylar ensures that client-side application code is authentic, even if the server is malicious. Results with a prototype of Mylar built on top of the Meteor framework are promising: porting 6 applications required changing just 36 lines of code on average, and the performance overheads are modest, amounting to a 17% throughput loss and a 50 ms latency increase for sending a message in a chat application.