• No results found

SECURITY OF CLOUD STORAGE AND CLOUD COMPUTING

N/A
N/A
Protected

Academic year: 2021

Share "SECURITY OF CLOUD STORAGE AND CLOUD COMPUTING"

Copied!
28
0
0

Loading.... (view fulltext now)

Full text

(1)

SECURITY OF CLOUD STORAGE AND

CLOUD COMPUTING

GIRI PRANEETH KOMMALAPATI VENKAT RAMAN SRIPERUMBUDUR ECE 646

Final Presentation

(2)

Introduction

 Save and access the files online.

 Data stored in the cloud can be accessed from anywhere.

 There are many security threats faced by the User and the Cloud Service Provider.

 This cloud storage can be trusted when there is enough security from the server side.

 There are many security issues with the cloud computing. These

security concerns are faced by both the providers and the consumers.  In order to protect the data, the providers/organizations must ensure

that the infrastructure is secure and the data of the consumers must be protected.

(3)

MOTIVATION

There is a huge amount of data that is stored in the cloud. Over the

years many popular cloud services like Dropbox, Amazon cloud

service, iCloud, etc. have been attacked by the hackers.

Hackers attack the cloud and steal the information of many users.

Although there are many attacks on the cloud, it is very important to

store the sensitive data due to its huge advantages.

Reducing or eliminating the problem of loosing sensitive data

through reliable security at the client side.

Fundamental services like confidentiality, availability, integrity and

reliability are required for the consumers which are rendered by the

CSP.

(4)

Hypothesis

Main focus is on the analytical assessment of deployment of

cryptools to safeguard the data. Some services a CSP must render

are-

Confidentiality: The data stored by the consumer must not be

accessed by any other person including the service provider.

Availability: The data must be accessible from anywhere from any

computer/mobile phones, etc.

Integrity: The data must not be modified by anyone other than the

consumer by maintaining data integrity.

(5)

CRYPTOOLS

The tools which we are using out of many for encryption are:

SharedSafe Launcher for Windows

Cloudfogger for Mac

BoxCryptor for Windows

Viivo SecretSync for Android

AES Crypt for Windows

(6)

CLIENT

Cloud

Storage

Encryption& Decryption Tools

BASIC BLOCK DIAGRAM

(7)

SHAREDSAFE LAUNCHER

simple way to share files on our FTP, e-mail, Dropbox with friends

& co-workers.

encrypts files with the well known AES-256 (Advanced Encryption

Standard) and is an Open Source with client side encryption.

protects files and file names before uploading.

automatically shares files in the background and is available to

operate offline.

(8)

Step-1

• Sharedsafe

(9)

Step-2

• Password created and safekey generated. • Folder syncs automatically • Client-side encryption

(10)

BOXCRYPTOR

Fast and easy Encryption

available for all the cloud storage providers like Dropbox, Sky drive,

Google Drive, etc.

supports all the clouds that use the WebDAV standard such as Cubby,

Strato HiDrive and Owncloud.

PGP can be used for sharing the files.

It creates a Virtual Drive on our computer that allows us to encrypt

our files locally before uploading them to the cloud.

(11)

BOX CRYPTOR ENCRYPTION (CLIENT SIDE)

A

KEY

ENCRYPTION PRIVATE KEYENCRYPTED RSA

PRIVATE KEY

(12)

BOX CRYPTOR ENCRYPTION (SERVER SIDE)

A

ENCRYPTION ENCRYPTED FILE ---ENCRYPTED KEY AES-256 KEY ENCRYPTION With RSA public key FILE CLOUD

(13)

BOX CRYPTOR DECRYPTION

A RSA KEY DECRYPTION AES 256 DECRYPTION PASSWORD PRIVATE KEY A KEY ENCRYPTED FILE ---ENCRYPTED KEY DECRYPTION FILE CLOUD

(14)
(15)
(16)
(17)

VIIVO

• VIIVO is a client side encryption tool used in android operating system.

• uses RSA 2048 and AES 256 algorithms to encrypt the data by creating an RSA key pair.

• The private key is secured with the password using PBKDF2 (Password-Based Key Derivation Function 2).

• The files are encrypted using AES-256 before they are uploaded in to the cloud.

• Most widely used by accountants, attorneys and Govt. & Health Care in the country.

(18)

VIIVO ENCRYPTION

RSA PRIVATE KEY

PASSWORD (PBKDF2) ENCRYPTED KEY FILE ENCRYPTED FILE (USING AES-256) CLOUD

(19)
(20)

AES CRYPT

AES encrypts files using AES encryption.

Files encrypted on one platform can be decrypted in other

platforms.

After encrypting the files locally we have to upload them to the

cloud.

(21)
(22)
(23)
(24)

DISKCRYPTOR

It offers encryption for all disk partitions.

It uses AES-256, Twofish, Serpent and also their combinations.

By cascading the algorithms, even if one algorithms is broken

(25)

CLOUDFOGGER

• Cloudfogger for MAC allows manual encryption and decryption of files.

• Uses AES-256 and RSA-4096 algorithm for the encryption of files.

• Private key is encrypted using the RSA-4096 algorithm.

(26)

Observations

• BoxCryptor secures the file that are uploaded into dropbox by encrypting them with a safe key.

• SharedSafe is used for sharing the files and file names securely using safe key.

• SharedSafe when a file is uploaded, it’s then encrypted and sent to a folder called My Safes.

• All the cryptools uses RSA-4096 and AES-256 algorithms for encryption of keys and files respectively.

• Cloud Fogger also uses same encryption algorithms at the client side.

• AES Crypt can be used to encrypt the files locally.

• Security mechanisms of all the tools are identical.

(27)

TOOL ENCRYPTION ALGORITHM

USED SHARING PLATFORM

Boxcryptor Client Side RSA 4096

AES 256 YES Windows, MAC, iOS, Android

Viivo Client Side RSA 4096

AES 256 YES Windows, MAC, iOS, Android Sharedsafe Client Side RSA 4096

AES 256 YES Windows,MAC Cloudfogger Client Side RSA 4096

AES 256 Yes Windows, MAC, iOS, Android AES Crypt Single file

encryption Tool AES NO Windows, MAC,Linux DiskCryptor Local drive

encryption Tool AES-256, Twofish, Serpent

(28)

CONCLUSIONS

• Client side encryption is important before uploading data to the cloud.

• Through the analytical assessment of the cryptools, we found boxcryptor to better for encryption in various terms of confidentiality, availability,

reliability and ease of use.

• All the cryptools have the same algoriths in common, i.e., the RSA for key encryprion and AES for file encryption.

References

Related documents

The fact that cocoa methylxanthines and theobromine and caffeine increased the concentration of SREMs in plasma compared with the concentration that would be reached when CFs or

Then, a multi-objective model was developed for designing an integrated rail transit and bus network to maximize rail ridership and minimize total passenger travel time.. An

(Without these two items, the collection/test will not be performed). 3) You must sign an Employee Consent Form, such as Appendix F, in order to proceed with the test. 4) You

The hypothesis of this study on the positive CP minus EP winter rainfall anomalies is that the lower level southwesterly wind anomalies, positive specific humidity anomalies,

นักเรียน ม.5 ทุกคนที่เข้าร่วมโครงการฯ มีจิตสาธารณะ อาสาช่วยเหลือ และตระหนักถึง ความส าคัญของการบ าเพ็ญประโยชน์เพื่อสังคม เชิงปริมาณ นักเรียน ม.5 ที่เข้าร่วมโครงการฯ จ านวน

When choosing an enterprise cloud storage and file-sharing service, take into account security, manageability and users' ability to access and collaborate on files across

With end-to-end security, intelligent multi-tier data caching and support for cloud-based storage repositories, Maginatics provides an innovative and disruptive approach