• No results found

SOME SECURITY CHALLENGES IN CLOUD COMPUTING. Hoang N.V.

N/A
N/A
Protected

Academic year: 2021

Share "SOME SECURITY CHALLENGES IN CLOUD COMPUTING. Hoang N.V."

Copied!
55
0
0

Loading.... (view fulltext now)

Full text

(1)

SOME SECURITY CHALLENGES

IN CLOUD COMPUTING

(2)
(3)

"

pay-per-use

model

for

enabling

available,

convenient and

on-demand

network access to a

shared pool

of

configurable

computing resources

(e.g., networks, servers, storage, applications and

services) that can be

rapidly provisioned and

released

with

minimal management effort

or

service provider interaction.“

by NIST

(4)
(5)

Cloud providers bring in $2B in first quarter -- source: Synergy Research Group, May, 2013

The overall cloud market will hit $71 billion in 2015

Source: Gartner Company data, Macquarie Capital (USA), Jan. 2013

(6)
(7)
(8)
(9)
(10)

Trust me, please!

(11)

Broad

Attacking Surface

We have everything in the cloud.

(12)

Broad

Attacking Surface

Data breach

Malicious Insider

(13)

Broad

Attacking Surface

Many others yet to be identified ...

4

13

10

9

7

0

2

4

6

8

10

12

14

Before Year 2008

Year 2008

Year 2009

Year 2010

Year 2011

No. of Incidents with Unknown Causes by Year

(14)
(15)

Security challenges with storage outsourcing

(16)

Security challenges with storage outsourcing

Internal: Byzantine failure, management errors, software bugs, ...

External: malware, economically motivated attacks, ...

(17)

Security challenges with storage outsourcing

(18)
(19)
(20)
(21)

Security challenges with storage outsourcing

(Data Integrity)

Cloud currently offers no guarantee

Should we trust the cloud 100 percent

for the storage integrity?

Data owners need a means to ensure

continuous correctnesss of outsourced

cloud data.

(22)

Security challenges with storage outsourcing

(Data Integrity)

Is my data correctly stored?

Storage correctness proofs

(23)

Traditional

method for data integrity

message m

k

k

Generate tag:

tag

S(k, m)

tag

Verify tag:

V(k, m

, tag

) =

yes

Def:

MAC

I = (S,V) defined over (K,M,T) is a pair of algs:

S(k,m) outputs t in T

V(k,m,t) outputs yes or no

(24)

Secure Cloud Storage Auditing

Is my data correctly stored

(k

1

)

DATA

DATA’

MAC(

k

1

, DATA’)

MAC(k

1

,DATA)

Before putting data in the cloud, must calculate and store

(25)

Secure Cloud Storage Auditing

Security

Convenience

Overhead

Challenges

H

ave to explore tradeoffs to maintain low

communication and compution overhead

on both owner and server side.

(26)

Secure Cloud Storage Auditing

Challenges

Cope

with

frequent

cloud

data

changing

while ensuring continuous

data auditing

(27)

Public

Private

(28)

Batch auditing improves

efficiency and saves computation

and communication overhead.

(29)

Secure Cloud Storage Auditing

Solutions

Cloud

Server

σ1

m

1 σ2

m

2 σ4

m

4 σ1

m

1 σ2

m

2 σ3

m

3 σ4

m

4

σn

m

n σ1

m

1 σ2

m

2 σ

μ

+

.

(30)

Redundantly stores data in multiple facilities and on multiple devices with each facility.

Can we trust?

(31)

Security challenges with storage outsourcing

(Data Integrity)

? F file

return F file

Cloud storage provider claims to store

three distinct copies

of my file for resillience.

Can we trust? No, if they can’t

prove it (Redundancy)

?

(32)

Security challenges with storage outsourcing

File F can survive two disk crashes

Disk 2

Disk 3

Disk 4

Disk 5

Disk 1

Virtual

Virtual

Virtual

Virtual

Virtual

F

F

F

F

A single disk crash can destroy F file

Virtualization is a complication.

We need proofs of data redundancy on the

physical layer.

(33)

Proof of redundancy

Solutions

Eeta Pizza Pi Cheapskate Pizza

“Six pizzas!”

The Pizza Oven Protocol (Juels A. 2011)

Network latency

Drive read time

(34)

as well as encryption for both secure transit and secure storage at

rest.

(35)
(36)
(37)

Security challenges with storage outsourcing

(Data leakage)

DATA

DATA

DATA

le ak ag e
(38)

Security challenges with storage outsourcing

(Data leakage)

DATA

E( ,DATA)

le ak ag e

E( ,DATA)

(39)

Services Front End Storage Back End

Security challenges with storage outsourcing

(Data leakage)

DATA leakage

(40)

12/2013

9/2014

10/2014

09/2010

05/2013

Sensitive data must be encrypted before

putting on the cloud server

(41)

Data

Ultiliztion

Data

Encryption

(42)
(43)

Whitten A., Tygar J. D., Why Johnny can’t encrypt: a usability of

evaluation of PGP 5.0, SSYM'99 Proceedings of the 8th conference on

USENIX Security Symposium

(44)
(45)

Data Encryption vs Data Utilization

Solutions

[Goldreich-Ostrovsky92]

[Song-Wagner-Perrig-S&P00][Goh-ePrint-03, Chang-Mitzenmacher-ACNS05]

[Curtmola-Garay-Kamara-Ostrovsky-ccs06]

(46)

But, encryption is not always enough.

Access patterns

can leak sensitive information.

(47)

The client is able to read a document m

i

from the remote

database without revealing his/her choice i to the server.

The same as PIR; in addition, it is required that the client can

only

learn m

i

after protocol execution.

The client is able to read and write the remote database without

revealing his/her access pattern to the server.

(48)

Từ khoá được các chị em tìm kiếm nhiều nhất năm 2013 là từ đại gia.

(49)
(50)
(51)

Computation Outsourcing

DATA

f(DATA)

How to protect data

How to protect result (f(DATA))

(52)

Computation Outsourcing

Solutions

Gentry C., Fully Homomorphic Encryption Using Ideal Lattices, STOC 2009

Lauter K., Naehrig M., Vaikuntanathan V., Can Homomorphic Encryption be Practical? IACR Cryptology ePrint Archive 2011/405, 2011

Brakerski Z., Vaikuntanathan V., Efficient Fully Homomorphic Encryption from (Standard) LWE. In Proc. of FOCS, 2011, pp. 97-106

Brakerski Z., Gentry C., Vaikuntanathan V., (Leveled) fully homomorphic encryption without bootstrapping. In Proc. of ITCS, 2012, pp. 309-325

Brakerski Z., Fully Homomorphic Encryption without Modulus Switching from Classical GapSVP. IACR Cryptology ePrint Archive 2012/78, 2012

Seny Kamara and Lei Wei, Garbled Circuits via Structured Encryption, in Workshop on Applied Homomorphic Encryption (WAHC '13), April 2013

Seny Kamara and Mariana Raykova, Parallel Homomorphic Encryption, in Workshop on Applied Homomorphic Encryption (WAHC '13), April 2013

(53)

Computation Outsourcing

Solutions

Privacy preserving Datamining/Machine learning

Verykios V. S. et.al, State-of-the-art in privacy preserving data mining, ACM SIGMOD Record

Volume 33 Issue 1, March 2004 Pages 50 – 57.

Wang C. et.al, "Secure and Practical Outsourcing of Linear Programming in Cloud Computing,” in

Proc. of IEEE INFOCOM, 2011.

Wang C. et.al, OIRS: Outsourced Image Recovery Service from Compressive Sensing with Privacy

Assurance, in NDSS Short Talk, 2013.

(54)

“Trusting trust”

Whom do you trust?

Probability No

Sometimes Yes

(55)
a, Parallel Homomorphic Encryption

References

Related documents

Knowledge-intensive business services (KIBS) are specialised commercial service activities that create added value by creating, gathering and disseminating expertise, supporting

77 Id. Typically, advertising is considered to be a trade or business that is unrelated to the charity’s exempt purposes. Thus, the question remains whether the advertising

Cover: Research necessary to assure scientific computing integrity in both current and future extreme-scale architectures will likely need to explore both novel computer

The decision to make this move was based on wanting to improve the services available to women, children and young people with experience of domestic abuse and through the

Thelycum with a long grooved tongue like anterior plate partially ensheathed in a horse shoe like process formed by lateral plates.. Body pale yellow

By adding an appropriate lightweight security mechanism to secure the trust information in the routing packets, a hybrid protocol can be created which is less expensive than SAODV

To summarise the outline of the study: Chapter 2 presents the methodolo- gy; Chapter 3 describes the study area; Chapters 4 and 5 deal with urban eco- nomic residential

Relation to [MO13] On October 2013, we initially posted the results contained within this paper which include: a construction of a public key encryption scheme that is IND-CPA