State-free End-to-End Encrypted Storage and Chat Systems based on Searchable Encryption

State-free End-to-End Encrypted Storage and Chat Systems based on Searchable Encryption
复制标题

DOI:
10.5220/0011045200003179
复制
发表时间:
2021
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
K. Emura;Ryoma Ito;Sachiko Kanamori;R. Nojima;Yohei Watanabe
K. Emura;Ryoma Ito;Sachiko Kanamori;R. Nojima;Yohei Watanabe
中科院分区:
其他
文献类型:
--
作者:
K. Emura;Ryoma Ito;Sachiko Kanamori;R. Nojima;Yohei Watanabe

文献摘要

相似文献

:可搜索对称加密(SSE)引起了人们的广泛关注,因为它可以防止外部设备(例如云上)的数据泄露。 SSE 似乎能够有效地构建这样一个安全系统;然而,在实践中从 SSE 构建这样一个系统并不容易,因为必须设计其他部分,例如用户登录管理、定义关键字空间以及在通常没有公钥证书的多个用户之间共享密钥。在本文中,我们描述了基于无状态动态 SSE(DSSE)(Watanabe 等人,ePrint 2021)的两个系统的实现,即安全存储系统(针对单个用户)和聊天系统(针对多个用户)。除了渡边等人。 DSSE 协议中,我们采用安全多路径密钥交换 (SMKEX) 协议(Costea 等人,CCS 2018),该协议可以安全地抵御某些类别的不同步主动攻击者。它允许没有证书的聊天系统用户以安全的方式共享 DSSE 协议的密钥。要实现端到端加密,共享密钥必须保密;因此,我们必须考虑如何在用户的本地设备等设备上保存秘密。然而,这需要额外的安全假设,例如防篡改,并且似乎很难假设所有用户都拥有此类设备。因此,我们提出了一种结合 SMKEX 和登录信息(密码)的安全密钥协商协议,不需要额外的防篡改设备。结合所提出的密钥协商协议和底层无状态 DSSE 协议,允许知道密码的用户在多个设备上使用系统。
: Searchable symmetric encryption (SSE) has attracted significant attention because it can prevent data leakage from external devices, e.g., on clouds. SSE appears to be effective to construct such a secure system; however, it is not trivial to construct such a system from SSE in practice because other parts must be designed, e.g., user login management, defining the keyword space, and sharing secret keys among multiple users who usually do not have public key certificates. In this paper, we describe the implementation of two systems based upon the state-free dynamic SSE (DSSE) (Watanabe et al., ePrint 2021), i.e., a secure storage system (for a single user) and a chat system (for multiple users). In addition to the Watanabe et al. DSSE protocol, we employ a secure multipath key exchange (SMKEX) protocol (Costea et al., CCS 2018), which is secure against some classes of unsynchronized active attackers. It allows the chat system users without certificates to share a secret key of the DSSE protocol in a secure manner. To realize end-to-end encryption, the shared key must be kept secret; thus, we must consider how to preserve the secret on, for example, a user’s local device. However, this requires additional security assumptions, e.g., tamper resistance, and it seems difficult to assume that all users have such devices. Thus, we propose a secure key agreement protocol by combining the SMKEX and login information (password) that does not require an additional tamper-resistant device. Combining the proposed key agreement protocol and the underlying state-free DSSE protocol allow users who know the password to use the systems on multiple devices.