QRES: Quantitative Reasoning on Encrypted Security SLAs

04/12/2018
by   Ahmed Taha, et al.
0

While regulators advocate for higher cloud transparency, many Cloud Service Providers (CSPs) often do not provide detailed information regarding their security implementations in their Service Level Agreements (SLAs). In practice, CSPs are hesitant to release detailed information regarding their security posture for security and proprietary reasons. This lack of transparency hinders the adoption of cloud computing by enterprises and individuals. Unless CSPs share information regarding the technical details of their security proceedings and standards, customers cannot verify which cloud provider matched their needs in terms of security and privacy guarantees. To address this problem, we propose QRES, the first system that enables (a) CSPs to disclose detailed information about their offered security services in an encrypted form to ensure data confidentiality, and (b) customers to assess the CSPs' offered security services and find those satisfying their security requirements. Our system preserves each party's privacy by leveraging a novel evaluation method based on Secure Two Party Computation (2PC) and Searchable Encryption techniques. We implement QRES and highlight its usefulness by applying it to existing standardized SLAs. The real world tests illustrate that the system runs in acceptable time for practical application even when used with a multitude of CSPs. We formally prove the security requirements of the proposed system against a strong realistic adversarial model, using an automated cryptographic protocol verifier.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/24/2018

Survey on Secure Search Over Encrypted Data on the Cloud

Cloud computing has become a potential resource for businesses and indiv...
research
01/09/2019

A Security Framework for Cloud Data Storage(CDS) Based on Agent

The Cloud has become a new Information Technology(IT) model for deliveri...
research
07/31/2023

AMOE: a Tool to Automatically Extract and Assess Organizational Evidence for Continuous Cloud Audit

The recent spread of cloud services has enabled many companies to take a...
research
08/14/2023

Towards a Cloud-Based Ontology for Service Model Security – Technical Report

The adoption of cloud computing has brought significant advancements in ...
research
06/12/2018

A Blockchain-based Flight Data Recorder for Cloud Accountability

Many companies rely on Cloud infrastructures for their computation, comm...
research
02/12/2020

Efficient Cloud-based Secret Shuffling via Homomorphic Encryption

When working with joint collections of confidential data from multiple s...
research
01/29/2020

SLO-ML: A Language for Service Level Objective Modelling in Multi-cloud Applications

Cloud modelling languages (CMLs) are designed to assist customers in tac...

Please sign up or login with your details

Forgot password? Click here to reset