PASSAT: Single Password Authenticated Secret-Shared Intrusion-Tolerant Storage with Server Transparency

02/26/2021
by   Kiavash Satvat, et al.
0

In this paper, we introduce PASSAT, a practical system to boost the security assurance delivered by the current cloud architecture without requiring any changes or cooperation from the cloud service providers. PASSAT is an application transparent to the cloud servers that allows users to securely and efficiently store and access their files stored on public cloud storage based on a single master password. Using a fast and light-weight XOR secret sharing scheme, PASSAT secret-shares users' files and distributes them among n publicly available cloud platforms. To access the files, PASSAT communicates with any k out of n cloud platforms to receive the shares and runs a secret-sharing reconstruction algorithm to recover the files. An attacker (insider or outsider) who compromises or colludes with less than k platforms cannot learn the user's files or modify the files stealthily. To authenticate the user to multiple cloud platforms, PASSAT crucially stores the authentication credentials, specific to each platform on a password manager, protected under the user's master password. Upon requesting access to files, the user enters the password to unlock the vault and fetches the authentication tokens using which PASSAT can interact with cloud storage. Our instantiation of PASSAT based on (2, 3)-XOR secret sharing of Kurihara et al., implemented with three popular storage providers, namely, Google Drive, Box, and Dropbox, confirms that our approach can efficiently enhance the confidentiality, integrity, and availability of the stored files with no changes on the servers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/26/2018

Cloud Storage Forensic: hubiC as a Case-Study

In today society where we live in a world of constant connectivity, many...
research
01/21/2021

Cloud-Based Content Cooperation System to Assist Collaborative Learning Environment

Online educational systems running on smart devices have the advantage o...
research
03/02/2021

The Capacity Region of Distributed Multi-User Secret Sharing

In this paper, we study the problem of distributed multi-user secret sha...
research
01/10/2019

Collaborative Privacy for Web Applications

Real-time, online-editing web apps provide free and convenient services ...
research
03/19/2018

The environmental footprint of a distributed cloud storage

Every time we access a file on the Cloud, a chain of routing servers is ...
research
07/27/2018

Ubuntu One Investigation: Detecting Evidences on Client Machines

STorage as a Service (STaaS) cloud services has been adopted by both ind...

Please sign up or login with your details

Forgot password? Click here to reset