The content host services (like Dropbox, OneDrive, and Google Drive) used by enterprise customers are deployed either on premise or in cloud. Because users may store business-sensitive data (contents) in these hosting services, they may want to protect their data from disclosure to anyone else, even IT administrators. Unfortunately, even contents (files) are encrypted in the hosting services, they sometimes are still accessible to IT administrators today. The sensitive data could be exposed to public if the IT administrator turns malicious (like disgruntled employee) or his account is compromised by hackers. We propose an end-to-end encryption (E2EE) solution to address this challenge. The user data is encrypted at client side (mobile device) and remains encrypted in transit and at rest on server. Specifically, we design a new method to allow master secret recover and escrow, while protecting them from being accessed by malicious administrators. In addition, we present a content (file) encryption scheme that achieves privacy, and granular access control. And it can be seamlessly integrated with major content host services used by business users today.
翻译:企业客户使用的内容主机服务( 如 Droppox、 OneDrive 和 Google Drive ), 由企业客户使用的内容主机服务( 如 Dropper、 OneDrive 和 Google Drive ) 。 由于用户可以在这些主机服务中存储业务敏感数据( 内容), 他们可能希望保护数据不被披露给其他人, 甚至信息技术管理员。 不幸的是, 即使是内容( 文件) 也在托管服务中加密, 信息技术管理员今天也仍然可以访问它们。 如果信息技术管理员变坏( 像不高兴的雇员) 或他的账户受到黑客的破坏, 敏感数据可能会被公诸于众。 我们建议了一种终端对终端加密( E2EEE) 的解决方案来应对这一挑战。 用户数据在客户端( 移动设备) 进行加密, 并在服务器上继续加密 。 具体地说, 我们设计了一种新的方法, 允许主秘密回收和保管, 同时保护它们不被恶意管理者访问。 此外, 我们提出了一个内容( 文件) 加密计划可以实现隐私, 和颗粒访问控制 。 。 它可以与商业用户使用的主要主机服务 。