Visible to the public Brief Announcement: Towards Security and Privacy for Outsourced Data in the Multi-party Setting

TitleBrief Announcement: Towards Security and Privacy for Outsourced Data in the Multi-party Setting
Publication TypeConference Paper
Year of Publication2014
AuthorsMaffei, Matteo, Malavolta, Giulio, Reinert, Manuel, Schröder, Dominique
Conference NameProceedings of the 2014 ACM Symposium on Principles of Distributed Computing
PublisherACM
Conference LocationParis, France
ISBN Number978-1-4503-2944-6
Keywordscloud storage, GORAM, oblivious RAM, ORAM, privacy-enhancing technologies
Abstract

Cloud storage has rapidly acquired popularity among users, constituting a seamless solution for the backup, synchronization, and sharing of large amounts of data. This technology, however, puts user data in the direct control of cloud service providers, which raises increasing security and privacy concerns related to the integrity of outsourced data, the accidental or intentional leakage of sensitive information, the profiling of user activities and so on. We present GORAM, a cryptographic system that protects the secrecy and integrity of the data outsourced to an untrusted server and guarantees the anonymity and unlinkability of consecutive accesses to such data. GORAM allows the database owner to share outsourced data with other clients, selectively granting them read and write permissions. GORAM is the first system to achieve such a wide range of security and privacy properties for outsourced storage. Technically, GORAM builds on a combination of ORAM to conceal data accesses, attribute-based encryption to rule the access to outsourced data, and zero-knowledge proofs to prove read and write permissions in a privacy-preserving manner. We implemented GORAM and conducted an experimental evaluation to demonstrate its feasibility.

URLhttp://doi.acm.org/10.1145/2611462.2611508
DOI10.1145/2611462.2611508
Citation KeyMaffei:2014:BAT:2611462.2611508