Benchmarking Cryptographic Schemes for Securing Public Cloud Storages - (Practical Experience Report)

Benchmarking Cryptographic Schemes for Securing Public Cloud Storages - (Practical Experience Report)
复制标题

用于保护公共云存储安全的加密方案基准测试 -(实践经验报告)

DOI:
--
复制
发表时间:
2017
期刊:
IFIP International Conference on Distributed Applications and Interoperable Systems
影响因子:
--
通讯作者:
Laurent Réveillère
Laurent Réveillère
中科院分区:
--
文献类型:
--
作者:
Stefan Contiu;Emmanuel Leblond;Laurent Réveillère

文献摘要

被引文献

相似文献

在过去的几年里,许多研究都集中在公共云存储的安全和隐私问题上。密码原语通常用于确保用户数据的机密性、真实性和完整性。保密性是通过使用密钥加密算法来解决的,而完整性和真实性是通过使用信息认证码、安全散列或数字签名来实现的。用于保护不受信任的云存储的特定配置的选择在很大程度上取决于预期的安全级别、要存储的数据的大小和类型以及对这些数据的访问模式。在这项工作中,我们有兴趣克服缺乏对用于保护公共云存储的加密原语的成本和有效性进行全面比较的问题,并根据目标使用条件在它们之间进行明智的选择。我们描述了一个独立的实验研究的结果,六个加密方案,代表的主要设计方案。我们的实践经验报告表明,对于给定情况(例如大部分小文件的写入繁重工作负载)的最佳方案不一定最适合于不同的情况(例如大文件的只读工作负载)。我们确定了与这些差异相关的方案特征,并讨论了每个设计的优点和缺点。我们的实验框架和结果可供社区公开使用。
Much research has focused during the last years on the security and privacy concerns of public cloud storages. Cryptographic primitives are commonly used to ensure user data confidentiality, authenticity and integrity. Confidentiality has been addressed by the use of symmetric-key encryption algorithms, while integrity and authenticity have been achieved by using message authentication codes, secure hashes or digital signatures. The choice of a specific configuration for securing an untrusted cloud storage highly depends on the expected security level, the size and type of data to store and the access pattern to these data. In this work, we are interested in overcoming the lack of comprehensive comparison of the costs and effectiveness of cryptographic primitives for securing public cloud storage, and ease an informed choice between them based on target usage conditions. We describe the results of an independent experimental study of six cryptographic schemes, representative of the principal design alternatives. Our practical experience report reveals that the best scheme for a given situation, such as a write-heavy workload of mostly small files, is not necessarily the most appropriate for a different situation such as a read-only workload of large files. We identify the scheme characteristics that are correlated with these differences and discuss the pros and cons of each design. Our experimental framework and results are available in the open for use by the community.