Secure deduplication of encrypted data without additional independent servers

Jian Liu, N. Asokan, Benny Pinkas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

181 Scopus citations

Abstract

Encrypting data on client-side before uploading it to a cloud storage is essential for protecting users'privacy. However client-side encryption is at odds with the standard practice of deduplication. Reconciling client-side encryption with cross-user deduplication is an active research topic. We present the first secure cross-user deduplication scheme that supports client-side encryption without requiring any additional independent servers. Interestingly, the scheme is based on using a PAKE (password authenticated key exchange) protocol. We demonstrate that our scheme provides better security guarantees than previous efforts. We show both the effectiveness and the efficiency of our scheme, via simulations using realistic datasets and an implementation.

Original languageEnglish
Title of host publicationCCS 2015 - Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages874-885
Number of pages12
ISBN (Electronic)9781450338325
DOIs
StatePublished - 12 Oct 2015
Event22nd ACM SIGSAC Conference on Computer and Communications Security, CCS 2015 - Denver, United States
Duration: 12 Oct 201516 Oct 2015

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
Volume2015-October
ISSN (Print)1543-7221

Conference

Conference22nd ACM SIGSAC Conference on Computer and Communications Security, CCS 2015
Country/TerritoryUnited States
CityDenver
Period12/10/1516/10/15

Bibliographical note

Funding Information:
This work was supported in part by the "Cloud Security Services" project funded by the Academy of Finland (283135), the EU 7th Framework Program (FP7/2007-2013) under grant agreement n. 609611 (PRACTICE) and a grant from the Israel Ministry of Science and Technology. We thank Ivan Martinovic for suggesting the analogy between our system and web-caching proxies. We thank Billy Brumley, Kaitai Liang, and the reviewers for their valuable feedback.

Publisher Copyright:
© 2015 ACM.

Keywords

  • Cloud storage
  • Deduplication
  • PAKE
  • Semantically secure encryption

Fingerprint

Dive into the research topics of 'Secure deduplication of encrypted data without additional independent servers'. Together they form a unique fingerprint.

Cite this