The Experts below are selected from a list of 8418 Experts worldwide ranked by ideXlab platform
Jinjun Chen - One of the best experts on this subject based on the ideXlab platform.
-
efficient searchable symmetric encryption for storing multiple source dynamic social data on cloud
Journal of Network and Computer Applications, 2017Co-Authors: Jinjun ChenAbstract:Cloud computing has greatly facilitated large-scale data outsourcing due to its cost efficiency, scalability and many other advantages. Subsequent privacy risks force data owners to encrypt sensitive data, hence making the outsourced data no longer searchable. Dynamic Searchable Symmetric Encryption (DSSE) is an advanced cryptographic primitive addressing the above issue, which maintains efficient keyword search over dynamic encrypted data without disclosing much information to the Storage Provider. Existing DSSE schemes implicitly assume that original user data is centralized, so that a searchable index can be built at once. Nevertheless, especially in pervasive social networking applications, user-side data centralization is not reasonable. E.g., social chatting records are often separately distributed over multiple devices such as mobile phones, laptops, tablet computers, etc. In this paper, we propose the notion of Multi-Data-Source DSSE (MDS-DSSE), which allows each data source to build a local index individually and enables the Storage Provider to merge all local indexes into a global index afterwards. We propose a novel MDS-DSSE scheme, in which an adversary only learns the number of data sources, the number of entire data files, the access pattern and the search pattern, but not any other distribution information such as how data files or search results are distributed over data sources. We offer rigorous security proof of our scheme, and report experimental results to demonstrate the efficiency of our scheme.
-
efficient searchable symmetric encryption for storing multiple source data on cloud
Trust Security And Privacy In Computing And Communications, 2015Co-Authors: Jinjun ChenAbstract:Cloud computing has greatly facilitated large-scale data outsourcing due to its cost efficiency, scalability and many other advantages. Subsequent privacy risks force data owners to encrypt sensitive data, hence making the outsourced data no longer searchable. Searchable Symmetric Encryption (SSE) is an advanced cryptographic primitive addressing the above issue, which maintains efficient keyword search over encrypted data without disclosing much information to the Storage Provider. Existing SSE schemes implicitly assume that original user data is centralized, so that a searchable index can be built at once. Nevertheless, especially in cloud computing applications, user-side data centralization is not reasonable, e.g. an enterprise distributes its data in several data centers. In this paper, we propose the notion of Multi-Data-Source SSE (MDS-SSE), which allows each data source to build a local index individually and enables the Storage Provider to merge all local indexes into a global index afterwards. We propose a novel MDS-SSE scheme, in which an adversary only learns the number of data sources, the number of entire data files, the access pattern and the search pattern, but not any other distribution information such as how data files or search results are distributed over data sources. We offer rigorous security proof of our scheme, and report experimental results to demonstrate the efficiency of our scheme.
Vinod Vaikuntanatha - One of the best experts on this subject based on the ideXlab platform.
-
sieve cryptographically enforced access control for user data in untrusted clouds
Networked Systems Design and Implementation, 2016Co-Authors: Frank Wang, Nickolai Zeldovich, James Mickens, Vinod VaikuntanathaAbstract:Modern web services rob users of low-level control over cloud Storage--a user's single logical data set is scattered across multiple Storage silos whose access controls are set by web services, not users. The consequence is that users lack the ultimate authority to determine how their data is shared with other web services. In this paper, we introduce Sieve, a new platform which selectively (and securely) exposes user data to web services. Sieve has a user-centric Storage model: each user uploads encrypted data to a single cloud store, and by default, only the user knows the decryption keys. Given this Storage model, Sieve defines an infrastructure to support rich, legacy web applications. Using attribute-based encryption, Sieve allows users to define intuitively understandable access policies that are cryptographically enforceable. Using key homomorphism, Sieve can reencrypt user data on Storage Providers in situ, revoking decryption keys from web services without revealing new keys to the Storage Provider. Using secret sharing and two-factor authentication, Sieve protects cryptographic secrets against the loss of user devices like smartphones and laptops. The result is that users can enjoy rich, legacy web applications, while benefiting from cryptographically strong controls over which data a web service can access.
Steven M Bellovin - One of the best experts on this subject based on the ideXlab platform.
-
privacy enhanced access control for outsourced data sharing
Financial Cryptography, 2012Co-Authors: Mariana Raykova, Hang Zhao, Steven M BellovinAbstract:Traditional access control models often assume that the entity enforcing access control policies is also the owner of data and resources. This assumption no longer holds when data is outsourced to a third-party Storage Provider, such as the cloud. Existing access control solutions mainly focus on preserving confidentiality of stored data from unauthorized access and the Storage Provider. However, in this setting, access control policies as well as users’ access patterns also become privacy sensitive information that should be protected from the cloud. We propose a two-level access control scheme that combines coarse-grained access control enforced at the cloud, which provides acceptable communication overhead and at the same time limits the information that the cloud learns from his partial view of the access rules and the access patterns, and fine-grained cryptographic access control enforced at the user’s side, which provides the desired expressiveness of the access control policies. Our solution handles both read and write access control.
Chen J - One of the best experts on this subject based on the ideXlab platform.
-
Efficient searchable symmetric encryption for storing multiple source dynamic social data on cloud
'Elsevier BV', 2017Co-Authors: Liu C, Zhu L, Chen JAbstract:© 2016 Elsevier Ltd Cloud computing has greatly facilitated large-scale data outsourcing due to its cost efficiency, scalability and many other advantages. Subsequent privacy risks force data owners to encrypt sensitive data, hence making the outsourced data no longer searchable. Dynamic Searchable Symmetric Encryption (DSSE) is an advanced cryptographic primitive addressing the above issue, which maintains efficient keyword search over dynamic encrypted data without disclosing much information to the Storage Provider. Existing DSSE schemes implicitly assume that original user data is centralized, so that a searchable index can be built at once. Nevertheless, especially in pervasive social networking applications, user-side data centralization is not reasonable. E.g., social chatting records are often separately distributed over multiple devices such as mobile phones, laptops, tablet computers, etc. In this paper, we propose the notion of Multi-Data-Source DSSE (MDS-DSSE), which allows each data source to build a local index individually and enables the Storage Provider to merge all local indexes into a global index afterwards. We propose a novel MDS-DSSE scheme, in which an adversary only learns the number of data sources, the number of entire data files, the access pattern and the search pattern, but not any other distribution information such as how data files or search results are distributed over data sources. We offer rigorous security proof of our scheme, and report experimental results to demonstrate the efficiency of our scheme
-
Efficient searchable symmetric encryption for storing multiple source data on cloud
'Institute of Electrical and Electronics Engineers (IEEE)', 2015Co-Authors: Liu C, Zhu L, Chen JAbstract:© 2015 IEEE. Cloud computing has greatly facilitated large-scale data outsourcing due to its cost efficiency, scalability and many other advantages. Subsequent privacy risks force data owners to encrypt sensitive data, hence making the outsourced data no longer searchable. Searchable Symmetric Encryption (SSE) is an advanced cryptographic primitive addressing the above issue, which maintains efficient keyword search over encrypted data without disclosing much information to the Storage Provider. Existing SSE schemes implicitly assume that original user data is centralized, so that a searchable index can be built at once. Nevertheless, especially in cloud computing applications, user-side data centralization is not reasonable, e.g. an enterprise distributes its data in several data centers. In this paper, we propose the notion of Multi-Data-Source SSE (MDS-SSE), which allows each data source to build a local index individually and enables the Storage Provider to merge all local indexes into a global index afterwards. We propose a novel MDS-SSE scheme, in which an adversary only learns the number of data sources, the number of entire data files, the access pattern and the search pattern, but not any other distribution information such as how data files or search results are distributed over data sources. We offer rigorous security proof of our scheme, and report experimental results to demonstrate the efficiency of our scheme
Frank Wang - One of the best experts on this subject based on the ideXlab platform.
-
sieve cryptographically enforced access control for user data in untrusted clouds
Networked Systems Design and Implementation, 2016Co-Authors: Frank Wang, Nickolai Zeldovich, James Mickens, Vinod VaikuntanathaAbstract:Modern web services rob users of low-level control over cloud Storage--a user's single logical data set is scattered across multiple Storage silos whose access controls are set by web services, not users. The consequence is that users lack the ultimate authority to determine how their data is shared with other web services. In this paper, we introduce Sieve, a new platform which selectively (and securely) exposes user data to web services. Sieve has a user-centric Storage model: each user uploads encrypted data to a single cloud store, and by default, only the user knows the decryption keys. Given this Storage model, Sieve defines an infrastructure to support rich, legacy web applications. Using attribute-based encryption, Sieve allows users to define intuitively understandable access policies that are cryptographically enforceable. Using key homomorphism, Sieve can reencrypt user data on Storage Providers in situ, revoking decryption keys from web services without revealing new keys to the Storage Provider. Using secret sharing and two-factor authentication, Sieve protects cryptographic secrets against the loss of user devices like smartphones and laptops. The result is that users can enjoy rich, legacy web applications, while benefiting from cryptographically strong controls over which data a web service can access.