A Security Proxy to Cloud Storage Backends Based on an Efficient Wildcard Searchable Encryption
Title | A Security Proxy to Cloud Storage Backends Based on an Efficient Wildcard Searchable Encryption |
Publication Type | Conference Paper |
Year of Publication | 2018 |
Authors | Chung, S., Shieh, M., Chiueh, T. |
Conference Name | 2018 IEEE 8th International Symposium on Cloud and Service Computing (SC2) |
ISBN Number | 978-1-7281-0236-8 |
Keywords | Amazon S3, Buildings, cloud computing, cloud databases, cloud storage, cloud storage backends, composability, constantly small storage footprint, cryptography, database indexing, efficient encryption, efficient wildcard searchable encryption, Encryption, enterprises, file content, index database, Indexes, information retrieval, local index, local malicious staff, on-premises storage, potential storage solution, pubcrawl, resilience, Resiliency, Searchable encryption, security proxy, storage management, wildcard SE construction |
Abstract | Cloud storage backends such as Amazon S3 are a potential storage solution to enterprises. However, to couple enterprises with these backends, at least two problems must be solved: first, how to make these semi-trusted backends as secure as on-premises storage; and second, how to selectively retrieve files as easy as on-premises storage. A security proxy can address both the problems by building a local index from keywords in files before encrypting and uploading files to these backends. But, if the local index is built in plaintext, file content is still vulnerable to local malicious staff. Searchable Encryption (SE) can get rid of this vulnerability by making index into ciphertext; however, its known constructions often require modifications to index database, and, to support wildcard queries, they are not efficient at all. In this paper, we present a security proxy that, based on our wildcard SE construction, can securely and efficiently couple enterprises with these backends. In particular, since our SE construction can work directly with existing database systems, it incurs only a little overhead, and when needed, permits the security proxy to run with constantly small storage footprint by readily out-sourcing all built indices to existing cloud databases. |
URL | https://ieeexplore.ieee.org/document/8567384 |
DOI | 10.1109/SC2.2018.00026 |
Citation Key | chung_security_2018 |
- file content
- wildcard SE construction
- storage management
- security proxy
- searchable encryption
- Resiliency
- resilience
- pubcrawl
- potential storage solution
- on-premises storage
- local malicious staff
- local index
- information retrieval
- Indexes
- index database
- Amazon S3
- enterprises
- encryption
- efficient wildcard searchable encryption
- efficient encryption
- database indexing
- Cryptography
- constantly small storage footprint
- composability
- cloud storage backends
- cloud storage
- cloud databases
- Cloud Computing
- Buildings